- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi All, I need to collect logs from windows servers in the environment. We have Splunk ES on cloud. What are the options available
singhvishakha29
Engager
05-16-2019
02:42 AM
We need to decide on the best and easy option to collect all kinds of windows event logs
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
05-16-2019
06:15 AM
The answer is the same for non-cloud users and those who don't have ES. Install a universal forwarder on each Windows server then enable the inputs for the desired logs.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
singhvishakha29
Engager
05-16-2019
08:00 AM
installing a universal forwarder on each windows doesn't seem feasible here. Can we use WMI instead. If yes, i suppose there are limitations on the types of logs that can be collected (no registry logs, AD logs etc). Please correct me if I am wrong
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
05-16-2019
12:35 PM
Yes, WMI is an option, but not a good one. WMI will affect the target server's performance more than a forwarder will.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
