Installation

Splunk_TA_Windows to be installed on Linux machines

amulay26
Path Finder

I am trying to get the windows events logs on Windows hosts by installing a forwarder and Splunk_TA_windows on windows machines.

  1. Do I need to install the the TA on the indexer which is a Linux host?
  2. Will the linux host be able to collect data?

Any help will be appreciated.

Thank you.

Tags (1)

VatsalJagani
SplunkTrust
SplunkTrust

Hello @amulay26,
You need to install TA_Windows on forwarder, indexer and search head all three layer.

  • Forwarder - You need to configure inputs.conf file for the data collection (
  • Indexer and Search Head - It is required for different purpose then the data collection. You must require TA_Windows on search head and indexer for the purpose of index time and search field extraction, index creation and lot more. On indexer data collection won't start so that will not be dependent on OS.

http://docs.splunk.com/Documentation/Splunk/7.1.3/Indexer/Indextimeversussearchtime (Field extraction)

0 Karma

deepashri_123
Motivator

Hey@amulay26,

Yes you need to install Splunk_TA_Windows on your indexer . It doesn't depend on the OS of the indexer.
Refer this link:
http://docs.splunk.com/Documentation/WindowsAddOn/5.0.0/User/Install

Let me know if this helps!!

kmorris_splunk
Splunk Employee
Splunk Employee

@deepashri_123 is correct. I think the docs make it a bit confusing on this. The only reason the indexers would need to be Windows, is if you were also ingesting locally on the indexers as well.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...