Fresh install (not in production yet) so I can reconfigure as necessary.
Distributed deployment, all Splunk servers are Linux; 1 searchhead, 3 indexer cluster, 1 deployment server
Getting an e...
Hi there,
I installed my brand new splunk 6.0.2 installation in a windowsonly network. I installed the Add-on (Splunk_TA_windows) on alle forwarders and the new SplunkAppforWindows I...
...Add-onforWindows and the indexes.conf from theSplunkAppforWindowsInfrastructure don't match up.
Inputs.conf from theSplunk Add-onforWindows, which I deployed to my Universal For...
...odular input "jmx" defined inside theapp "Splunk_TA_jmx": Introspecting scheme=jmx: script running failed (exited with code 1).
Some background:
We set up SPLUNK_TA_jmx for testing on a Windows s...
...We can see events arriving in msad. (Please have a look at below screenshot from the guided setup in theSplunkAppforWindowsInfrastructure.) Any ideas?
If we intend to use theSplunkAppforWindowsInfrastructure to collect security-related logs (such as Logon/Logoff, GP changes, etc.), should we installtheForwarders, Indexers and SearchHead a...
...eployment will separate out the roles to different servers.
I would like to deploy theSplunkAppforWindowsInfrastructureapp and the other Windows add-ons to my Windows Universal Forwarders, as l...
...y are (i.e. Azure, AWS, on-premise, etc.) Potential solutions: Install a forwarder on every VM and back haul the traffic across the VPN to on-premise indexers. I don't want to pay the VPN c...
I can not find "WinEventLog:Security" onthe source type selection screen when uploading data.
And I can't find it in sourcetype list screen too.
However, the logs have a definite source type d...