Getting Data In

Windows TA deployment indexer/forwarder

sonicZ
Contributor

Basically i am trying this deployment

windows hosts: Installed the Windows TA app/configured inputs.conf with proper perfmon inputs etc.

Search head: Installed Windows app, should be able to see windows TA data, since TA app and windows app are not supported on the same instance of Splunk?

indexer: Nothing installed.

After reading the docs they say the windows TA app can be installed on indexers but does it need to be in order for the windows TA forwarded data to properly index?
http://docs.splunk.com/Documentation/WindowsApp/latest/User/InstalltheSplunkTechnologyAdd-onforWindo...

Tags (1)
0 Karma
1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

Hi,

Yes, that needs to go on your indexers.

jcoates-mba:apps jcoates$ grep index Splunk_TA_windows/README.txt 
Has index-time operations: true, this technology add-on must be placed on indexers

View solution in original post

jcoates_splunk
Splunk Employee
Splunk Employee

Hi,

Yes, that needs to go on your indexers.

jcoates-mba:apps jcoates$ grep index Splunk_TA_windows/README.txt 
Has index-time operations: true, this technology add-on must be placed on indexers

View solution in original post

crosset2
Engager

Thanks Jcoates, I installed the app on all 8 of our production indexers in the $SPLUNK_HOME\etc\apps directory
bounced them last week, but still no windows related events from the host with the TA app.
I am submitting a case on this..

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!