...howing up in "Forwarder Management" but I can't seem to get event logs from any servers except the deployment server. I have enabled firewall ports outbound 8089 and inbound 9997 on the deployment server. T...
I want to monitor a Windows Event log such as Microsoft-Windows-WLAN-AutoConfig/Operational . I was able to get it working via the Universal Forwarder. Is it possible to do it via WMI from the S...
Hi Splunk community,
I want to have a single forwarder for every on-premise domain controller in my network, instead of installing a universal forwarder on every domain controller.
How do I go ...
I'm using a Windows Splunk server to collect WMIdata. How can I use that to send data to my main Splunk installation, which is Linux? I'm looking for the best practice- what's the easiest way to d...
I have installed Windows infrastructure app on Splunk search head (which is a server) The app requires multiple indexes(msad, perfmon, wineventlog) and all indexes are receiving data except f...
Hi there,
I have the following issue detected in our environment and I'm not sure where the problem comes from.
We have several Windows Server monitored with a heavy forwarder. The Event logs a...
Hi All,
I have Windows 2008 64bit & Windows 2003 64bit server.
I've installed splunk 4.2.4 64bit(via administrator user) on my machines and also installed splunk windows app for monitoring m...
I have a lot of remote Windows servers that I would like to install Splunk on. It will take forever to manually do this, so I was wondering if I could use Group Policy Objects in Active Directory t...