All Apps and Add-ons

Splunk cannot find "admin/win-event-log-collections".

mikeely
Path Finder

New install of Splunk on 64-bit RHEL, configured universal forwarder on 32-bit win2k3 machine and see some events coming through so I know at some level it's working. Problem is, when I go to look at perf graphs they all say "no data found" and the associated WMI Management link leads to the 404 error given in the title here. I can also get the same 404 error when I click the "Get more data into your Splunk: Get remote event logs via WMI." link as well.

Looks to me like the Windows app is somehow broken on my install. Thoughts?

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

You can only collect data via WMI from a Windows version of Splunk, and then forward those to the Linux indexer. The UF (the one you have on Windows) unfortunately does not have a GUI for configuring WMI collection, but it can in fact do the collection as long as the correct configuration files are created and applied.

View solution in original post

mikeely
Path Finder

So would this be a job for deployment server? I'm guessing I'd use a full-fledged windows forwarder just to create the configuration properly and then send that out to the other windows machines through deployment, but there are probably a few complications to this that aren't obvious to me.

0 Karma

mikelanghorst
Motivator

A deployment server would make the process of getting the configs to the individual servers easier.

You'll be best off by using a single windows host to configure manually first: http://www.splunk.com/base/Documentation/4.2.2/Data/MonitorWMIdata create a directory under that forwarders etc/apps. Then once you have it working on that host copy the directory you have to a deployment server then push it out from there.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You can only collect data via WMI from a Windows version of Splunk, and then forward those to the Linux indexer. The UF (the one you have on Windows) unfortunately does not have a GUI for configuring WMI collection, but it can in fact do the collection as long as the correct configuration files are created and applied.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...