Dear ,
I have cluster setup and we need to collect local logging logs from work station using WMI without install UF on targets so I need to know the pre-request .
It can be done:
https://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorWMIdata
But it is sub-optimal to using a standard UF and has downsides and complications:
https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/TroubleshootingWMI
I would also consider using Windows Event Forwarding (WEF). WMI log collection has always been problematic for me at scale, since WMI breaks a lot. We use WEF with all our VDIs (45k+).
Have you reviewed this:
https://docs.splunk.com/Documentation/Splunk/8.0.2/Data/MonitorWMIdata