Getting Data In

Windows TA deployment indexer/forwarder

sonicZ
Contributor

Basically i am trying this deployment

windows hosts: Installed the Windows TA app/configured inputs.conf with proper perfmon inputs etc.

Search head: Installed Windows app, should be able to see windows TA data, since TA app and windows app are not supported on the same instance of Splunk?

indexer: Nothing installed.

After reading the docs they say the windows TA app can be installed on indexers but does it need to be in order for the windows TA forwarded data to properly index?
http://docs.splunk.com/Documentation/WindowsApp/latest/User/InstalltheSplunkTechnologyAdd-onforWindo...

Tags (1)
0 Karma
1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

Hi,

Yes, that needs to go on your indexers.

jcoates-mba:apps jcoates$ grep index Splunk_TA_windows/README.txt 
Has index-time operations: true, this technology add-on must be placed on indexers

View solution in original post

jcoates_splunk
Splunk Employee
Splunk Employee

Hi,

Yes, that needs to go on your indexers.

jcoates-mba:apps jcoates$ grep index Splunk_TA_windows/README.txt 
Has index-time operations: true, this technology add-on must be placed on indexers

crosset2
Engager

Thanks Jcoates, I installed the app on all 8 of our production indexers in the $SPLUNK_HOME\etc\apps directory
bounced them last week, but still no windows related events from the host with the TA app.
I am submitting a case on this..

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...