I installed a splunk forwarder on windows, and setup monitoring of remote wmi.
Configured splunk to run on a domain user, with permissions.
wmi.conf
[WMI:getmylogs]
disabled = 0
event_log_file = Security
index = default
interval = 5
server = secure.hiddencastle.kp
But cannot retrieve anything.
I do not see any wplunk-wmi.exe process
and I double check that I can access the remote logs with the user using wbemtest.exe wbemtest
Check if the wmi default monitor is enabled with a btool
splunk cmd btool inputs list script
[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]
disabled = 1
and it this is the case, enable it in $SPLUNK_HOME\etc\system\local\inputs.conf
[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]
disabled = 0
Check if the wmi default monitor is enabled with a btool
splunk cmd btool inputs list script
[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]
disabled = 1
and it this is the case, enable it in $SPLUNK_HOME\etc\system\local\inputs.conf
[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]
disabled = 0
It worked, after the restart we see events.
and the splunk-wmi.exe process shows up in my process explorer.