All Apps and Add-ons

Splunk cannot find "admin/win-event-log-collections".

mikeely
Path Finder

New install of Splunk on 64-bit RHEL, configured universal forwarder on 32-bit win2k3 machine and see some events coming through so I know at some level it's working. Problem is, when I go to look at perf graphs they all say "no data found" and the associated WMI Management link leads to the 404 error given in the title here. I can also get the same 404 error when I click the "Get more data into your Splunk: Get remote event logs via WMI." link as well.

Looks to me like the Windows app is somehow broken on my install. Thoughts?

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

You can only collect data via WMI from a Windows version of Splunk, and then forward those to the Linux indexer. The UF (the one you have on Windows) unfortunately does not have a GUI for configuring WMI collection, but it can in fact do the collection as long as the correct configuration files are created and applied.

View solution in original post

mikeely
Path Finder

So would this be a job for deployment server? I'm guessing I'd use a full-fledged windows forwarder just to create the configuration properly and then send that out to the other windows machines through deployment, but there are probably a few complications to this that aren't obvious to me.

0 Karma

mikelanghorst
Motivator

A deployment server would make the process of getting the configs to the individual servers easier.

You'll be best off by using a single windows host to configure manually first: http://www.splunk.com/base/Documentation/4.2.2/Data/MonitorWMIdata create a directory under that forwarders etc/apps. Then once you have it working on that host copy the directory you have to a deployment server then push it out from there.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You can only collect data via WMI from a Windows version of Splunk, and then forward those to the Linux indexer. The UF (the one you have on Windows) unfortunately does not have a GUI for configuring WMI collection, but it can in fact do the collection as long as the correct configuration files are created and applied.

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...