Splunk Enterprise Security

Collect remote event logs through WMI

16gym
New Member

My splunk server and remote host server is in the same network.
In the Splunk server, I went Settings-->Data inputs-->Remote Event Log Collection-->New event log collection, and typed the following:
Event Log collection name: Test
Choose logs from this host: 10.22.85.177

An error message "Unable to get wmi classes from host '10.22.85.177'. This host may not be reachable or WMI may be misconfigured." is shown.
I configured them according to this post: https://splk.it/2SIjPft
but it didn't work.

I would like to know how should I configure the WMI settings on the remote host?
Thanks!

0 Karma

deepashri_123
Motivator

Hey@16gym,

You can try referring this link:
https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/MonitorWMIdata

Let me know if this helps!!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...