Getting Data In

Windows TA deployment indexer/forwarder

sonicZ
Contributor

Basically i am trying this deployment

windows hosts: Installed the Windows TA app/configured inputs.conf with proper perfmon inputs etc.

Search head: Installed Windows app, should be able to see windows TA data, since TA app and windows app are not supported on the same instance of Splunk?

indexer: Nothing installed.

After reading the docs they say the windows TA app can be installed on indexers but does it need to be in order for the windows TA forwarded data to properly index?
http://docs.splunk.com/Documentation/WindowsApp/latest/User/InstalltheSplunkTechnologyAdd-onforWindo...

Tags (1)
0 Karma
1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

Hi,

Yes, that needs to go on your indexers.

jcoates-mba:apps jcoates$ grep index Splunk_TA_windows/README.txt 
Has index-time operations: true, this technology add-on must be placed on indexers

View solution in original post

jcoates_splunk
Splunk Employee
Splunk Employee

Hi,

Yes, that needs to go on your indexers.

jcoates-mba:apps jcoates$ grep index Splunk_TA_windows/README.txt 
Has index-time operations: true, this technology add-on must be placed on indexers

crosset2
Engager

Thanks Jcoates, I installed the app on all 8 of our production indexers in the $SPLUNK_HOME\etc\apps directory
bounced them last week, but still no windows related events from the host with the TA app.
I am submitting a case on this..

0 Karma
Get Updates on the Splunk Community!

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...