Getting Data In

Windows TA deployment indexer/forwarder

sonicZ
Contributor

Basically i am trying this deployment

windows hosts: Installed the Windows TA app/configured inputs.conf with proper perfmon inputs etc.

Search head: Installed Windows app, should be able to see windows TA data, since TA app and windows app are not supported on the same instance of Splunk?

indexer: Nothing installed.

After reading the docs they say the windows TA app can be installed on indexers but does it need to be in order for the windows TA forwarded data to properly index?
http://docs.splunk.com/Documentation/WindowsApp/latest/User/InstalltheSplunkTechnologyAdd-onforWindo...

Tags (1)
0 Karma
1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

Hi,

Yes, that needs to go on your indexers.

jcoates-mba:apps jcoates$ grep index Splunk_TA_windows/README.txt 
Has index-time operations: true, this technology add-on must be placed on indexers

View solution in original post

jcoates_splunk
Splunk Employee
Splunk Employee

Hi,

Yes, that needs to go on your indexers.

jcoates-mba:apps jcoates$ grep index Splunk_TA_windows/README.txt 
Has index-time operations: true, this technology add-on must be placed on indexers

crosset2
Engager

Thanks Jcoates, I installed the app on all 8 of our production indexers in the $SPLUNK_HOME\etc\apps directory
bounced them last week, but still no windows related events from the host with the TA app.
I am submitting a case on this..

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...