Splunk Search

Get windows Local login logs using WMI

khalidewaidah
Explorer

Dear ,
I have cluster setup and we need to collect local logging logs from work station using WMI without install UF on targets so I need to know the pre-request .

Tags (1)
0 Karma

woodcock
Esteemed Legend
0 Karma

xavierashe
Contributor

I would also consider using Windows Event Forwarding (WEF). WMI log collection has always been problematic for me at scale, since WMI breaks a lot. We use WEF with all our VDIs (45k+).

anmolpatel
Builder
0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...