Getting Data In

Windows Subsystem for Linux logging

mdmosaraf
New Member

Hi all,

Any idea what type of logs we can onboard for WSL2 and how we can do that.

Labels (2)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @mdmosaraf 

There is no official Splunk docs supporting WSL, however this link having some discussion around it which is about installing Splunk Enterprise. IS it possible to install Splunk on Ubuntu on Wind... - Splunk Community

If your requirement is to monitor WSL2 and Splunk Enterprise set-up is already running in your network in different host then i would give  a try installation of Splunk Universal Forwarder (UF), Linux version depends on 64/32 bit of your WLS2 OS. If that is successful then add-on Splunk Add-on for Unix and Linux | Splunkbase helps to extract some useful logs from Linux which will be installed on top of  UF.

Note: This is not official as per docs just a trail and test, Splunk might not support if you find issues with it. This may result into your WSL2 performance degradation as well if you are running critical apps just keep it in mind.

-------------------------------------------------------------

An upvote would be appreciated if it helps!

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...