Splunk Tech Talks
Deep-dives for technical practitioners.

My Start Will Go On: Splunk's TA for Windows Part 1

melissap
Splunk Employee
Splunk Employee

View our IT Tech Talk,  My Start Will Go On: Splunk’s TA for Windows Part 1 where we introduce the Windows TA, showing you how you can gain rapid insights and operational visibility into Windows environments.

Join us for part one to see:

  • An introduction the TA
  • Demos showing set-up and available out-of-the-box content

Tech Talk discussions remain open for two weeks following the live Tech Talk event. Have more questions? Check out our  Splunk Add-On for Microsoft Windows conversations in Splunk Answers community for more!

melissap
Splunk Employee
Splunk Employee

Here is the Q&A from the live Tech Talk.

Recapping for all.

 

Q: For this to work does $SPLUNK_HOME environment variable need to be created? Our Windows Admin seems to think so.
A: I didn't need to. I could think that this is needed when you are not running with the standard config.
 
Q: How can I modify a Splunk Universal forwarder after it's been installed on a Windows server? My Enterprise Splunk is running on a Windows server and not Linux
A: Same with me: Splunk Server on Linux, remote Windows Servers and clients. You do this through deploying the configuration (for example your changed windows_ta) via the deployment server (or any other deployment mechanism of your choice).
 
Q: ## Enable below powershell and monitor stanzas to get WindowsUpdate.log for Windows 10 and Server 2016 ## Below stanza will automatically generate WindowsUpdate.log daily [powershell://generate_windows_update_logs] script = ."$SplunkHome\etc\apps\Splunk_TA_windows\bin\powershell\generate_windows_update_logs.ps1" schedule = 0 */24 * * * disabled = 0 index=windows ## Below stanza will monitor the generated WindowsUpdate.log in Windows 10 and Server 2016 [monitor://$SPLUNK_HOME\var\log\Splunk_TA_windows\WindowsUpdate.log] disabled = 0 index=windows
A: Cheers! That's awesome. Could you maybe post this at answers.splunk.com?
 
Q: Should it be deployed from a Deployment Server (using server classes) and/or Cluster Master?
A: dDeployment server
 
melissap
Splunk Employee
Splunk Employee