In this case I suspect starting at the end and working backwards might be helpful. WMI - While it's not terrible for some small testing, I'd suggest not using it because it's *far* more difficult to...
See more...
In this case I suspect starting at the end and working backwards might be helpful. WMI - While it's not terrible for some small testing, I'd suggest not using it because it's *far* more difficult to set up, manage, and deal with than using a Universal Forwarder on the actual endpoint. The UF installs easily, is tiny and efficient, and *also uninstalls easily and completely too*. And don't take my word for it, Splunk also has docs for this. I know, it'll sound like they're "pushing the UF for some nefarious reason" but there's nothing nefarious about it, it's just better in nearly every way than using WMI. https://docs.splunk.com/Documentation/Splunk/9.2.1/Data/ConsiderationsfordecidinghowtomonitorWindowsdata Even neater is to spend the few minutes - it's not terribly hard! - to set up the forwarders to use your splunk as a deployment server. Then on your Splunk you *can* create remote inputs, but instead of being some unreliable "pull" over wmi, it'll be configs sent to the UF to tell it how to collect them locally and send in those logs. And with those changes, all your complaints about WMI will disappear. I mean, you may have new complaints, but they won't be about WMI. "Could not find userBaseDN on the LDAP server" is just generally just 'incorrect configuration'. Some time in ADSI Edit and the various AD tools may help here. And network devices - it truly depends on your familiarity with syslog etc, but even having had been a Windows admin I found getting network device data into Splunk was at least as easy as getting Windows data in. You literally started with what I think is the hard part. There's one or two extra moving parts, but they're all simple, isolated parts in the device->syslog->UF->Splunk path that are easily understood and worked with, vs. the "magic" and weird stuff that the Windows event logs can sometimes conjure up. And a note - we're all 100% volunteers here. I'm sure the comment about "no time wasters" was just frustration speaking, and that's understandable. But it did come off as somewhat unkind and I'm sure you would have gotten something of an answer much quicker without that. No one here that I've ever seen wants to waste your time. We're all spending our free time trying to help people.