Splunk Tech Talks
Deep-dives for technical practitioners.

My Start Will Go On: Splunk's TA for Windows Part 1

melissap
Splunk Employee
Splunk Employee

View our IT Tech Talk,  My Start Will Go On: Splunk’s TA for Windows Part 1  where we introduce the Windows TA, showing you how you can gain rapid insights and operational visibility into Windows environments.

 

Join us for part one to see:

  • An introduction the TA
  • Demos showing set-up and available out-of-the-box content

Tech Talk discussions remain open for two weeks following the live Tech Talk event. Have more questions? Check out our  Splunk Add-On for Microsoft Windows conversations in Splunk Answers community for more!

melissap
Splunk Employee
Splunk Employee

Here is the Q&A from the live Tech Talk.

Recapping for all.

 

Q: For this to work does $SPLUNK_HOME environment variable need to be created? Our Windows Admin seems to think so.
A: I didn't need to. I could think that this is needed when you are not running with the standard config.
 
Q: How can I modify a Splunk Universal forwarder after it's been installed on a Windows server? My Enterprise Splunk is running on a Windows server and not Linux
A: Same with me: Splunk Server on Linux, remote Windows Servers and clients. You do this through deploying the configuration (for example your changed windows_ta) via the deployment server (or any other deployment mechanism of your choice).
 
Q: ## Enable below powershell and monitor stanzas to get WindowsUpdate.log for Windows 10 and Server 2016 ## Below stanza will automatically generate WindowsUpdate.log daily [powershell://generate_windows_update_logs] script = ."$SplunkHome\etc\apps\Splunk_TA_windows\bin\powershell\generate_windows_update_logs.ps1" schedule = 0 */24 * * * disabled = 0 index=windows ## Below stanza will monitor the generated WindowsUpdate.log in Windows 10 and Server 2016 [monitor://$SPLUNK_HOME\var\log\Splunk_TA_windows\WindowsUpdate.log] disabled = 0 index=windows
A: Cheers! That's awesome. Could you maybe post this at answers.splunk.com?
 
Q: Should it be deployed from a Deployment Server (using server classes) and/or Cluster Master?
A: dDeployment server
 
melissap
Splunk Employee
Splunk Employee
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...