Installation

Splunk_TA_Windows to be installed on Linux machines

amulay26
Path Finder

I am trying to get the windows events logs on Windows hosts by installing a forwarder and Splunk_TA_windows on windows machines.

  1. Do I need to install the the TA on the indexer which is a Linux host?
  2. Will the linux host be able to collect data?

Any help will be appreciated.

Thank you.

Tags (1)

VatsalJagani
SplunkTrust
SplunkTrust

Hello @amulay26,
You need to install TA_Windows on forwarder, indexer and search head all three layer.

  • Forwarder - You need to configure inputs.conf file for the data collection (
  • Indexer and Search Head - It is required for different purpose then the data collection. You must require TA_Windows on search head and indexer for the purpose of index time and search field extraction, index creation and lot more. On indexer data collection won't start so that will not be dependent on OS.

http://docs.splunk.com/Documentation/Splunk/7.1.3/Indexer/Indextimeversussearchtime (Field extraction)

0 Karma

deepashri_123
Motivator

Hey@amulay26,

Yes you need to install Splunk_TA_Windows on your indexer . It doesn't depend on the OS of the indexer.
Refer this link:
http://docs.splunk.com/Documentation/WindowsAddOn/5.0.0/User/Install

Let me know if this helps!!

kmorris_splunk
Splunk Employee
Splunk Employee

@deepashri_123 is correct. I think the docs make it a bit confusing on this. The only reason the indexers would need to be Windows, is if you were also ingesting locally on the indexers as well.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...