Getting Data In

How to push Windows event and security logs to a *NIX Splunk server without deploying forwarders on the Windows servers?

judenaidoo
New Member

According to my understanding, WMI as a pull agent is available on Windows' deployment of Splunk only.

What are the options for either pushing logs from any native Windows server app, or pulling via any native *UNIX app where Splunk is deployed to get Windows event and security logs ?

The customer does NOT want to deploy forwarders on all his Windows servers.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

I'll comment that perhaps your customer is being a little short-sighted, but okay.

WMI as a pull-agent is available only on Windows, and is really undesirable. It requires lots more bandwidth and processing on each server. What you might be able to do is something like this:

You could use Windows Native Log forwarding via GPO to forward logs from all of your Windows servers to a single Windows-based collection node, and then run a forwarder on it. Similarly, have all of your *nix boxes use syslog forwarding to forward to a syslog-ng server and run a forwarder there to pick up.

You wind up with two extra servers - one Windows, one Unix - but no forwarders anywhere else.

0 Karma

judenaidoo
New Member

@dwaddle - Thanks for the prompt response. Yes, my customer is being a little short-sighted, but understandably so, as they have circa 300 MS servers and are very risk averse. The problem is limited just to the Windows environment, and I've proposed the idea of event-log forwarding to another windows server vm with a forwarder on there. I just wanted to see if there was any other option.
Thanks again for your input.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...