Getting Data In

Windows Event collection - A really basic question, Doh

kevbod
New Member

Guys, I want to use Splunk for some eval work on Windows 7 prof and server 2008 and 2012. I want to stick strictly to Universal Forwarders and not WMI. Am i reading this document link correctly below?

http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorwindowsdata

The words "Splunk Enterprise must run on Windows" says to me I have no option other than a Windows install of Splunk Enterprise and therefore my currently built Splunk Enterprise Red Hat server install is not fit for this purpose?

The documentation is good but pulling these simple strings together is not easy. Can anyone point me to a document that will answer these questions please?

0 Karma

Runals
Motivator

Nah - you are fine. Put the appropriate UFs on your Windows devices and have the data sent back to your Red Hat indexer(s). I get why the document looks confusing but haven't had any caffeine yet so can't concisely reword it.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...