Getting Data In

Will Splunk WMI inputs work on servers not in same domain?

maverick
Splunk Employee
Splunk Employee

I need to set up WMI polling on my Windows boxes that cannot run agents or belong to a domain.

With Splunk, is it possible to use local accounts for WMI polling provided that the permissions are set correctly?

0 Karma

maverick
Splunk Employee
Splunk Employee

If the machines are not in a domain, then you can query them from another stand-alone Windows server if the user name (i.e. the name Splunk is installed as on the collector) also exists as a local administrator on the target machine(s).

e.g. install splunk as myhost\foo, where $everyremotehost also has an account ‘foo’ with sufficient (probably local administrator) permissions.

Note: you will probably want to wrap that in a VPN or native IPSec, as without a domain, Windows reverts to NTLMv2, which I believe is crackable.

0 Karma

maverick
Splunk Employee
Splunk Employee

thanks and corrected!

0 Karma

mw
Splunk Employee
Splunk Employee

Your backslash was lost in myhost\foo

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...