Getting Data In

Collecting data from Windows host without forwarder or domain group

MHibbin
Influencer

Hi all,

I was wondering if anyone has had experience of collecting remote data for Splunk from a Windows device, where a forwarder can not be installed on the machine (due to support issues), and the device uses local authentication (i.e. is not in an AD domain group). Preferably not installing a third party file either.

Any thoughts on how this could be achieved? - obviously linux has native tools available to make this easy, apparently not with Windows.

Thanks in advance,

MHibbin

0 Karma
1 Solution

Kate_Lawrence-G
Contributor

Hi,

I can only think of 2 possible options:

  1. Remotely monitor the box over WMI - http://docs.splunk.com/Documentation/Splunk/4.3.2/Data/MonitorWindowsdata#Configure_remote_event_log...
  2. Or write a VB/Powershell script to get everything into a remote share that splunk can read it from there - http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorfilesanddirectories

Thanks!

Kate

View solution in original post

Kate_Lawrence-G
Contributor

Hi,

I can only think of 2 possible options:

  1. Remotely monitor the box over WMI - http://docs.splunk.com/Documentation/Splunk/4.3.2/Data/MonitorWindowsdata#Configure_remote_event_log...
  2. Or write a VB/Powershell script to get everything into a remote share that splunk can read it from there - http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorfilesanddirectories

Thanks!

Kate

MHibbin
Influencer

Thanks for the answer @Kate_Lawrence. However, as mentioned the windows machine does not use AD for authentication, WMI is out of the question (option #1).

We are going to look into sending the data using something like psftp/pscp to a windows forwarder and then have the EVTs/logs read/forwarded from there.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...