New install of Splunk on 64-bit RHEL, configured universal forwarder on 32-bit win2k3 machine and see some events coming through so I know at some level it's working. Problem is, when I go to look at perf graphs they all say "no data found" and the associated WMI Management link leads to the 404 error given in the title here. I can also get the same 404 error when I click the "Get more data into your Splunk: Get remote event logs via WMI." link as well.
Looks to me like the Windows app is somehow broken on my install. Thoughts?
You can only collect data via WMI from a Windows version of Splunk, and then forward those to the Linux indexer. The UF (the one you have on Windows) unfortunately does not have a GUI for configuring WMI collection, but it can in fact do the collection as long as the correct configuration files are created and applied.
So would this be a job for deployment server? I'm guessing I'd use a full-fledged windows forwarder just to create the configuration properly and then send that out to the other windows machines through deployment, but there are probably a few complications to this that aren't obvious to me.
A deployment server would make the process of getting the configs to the individual servers easier.
You'll be best off by using a single windows host to configure manually first: http://www.splunk.com/base/Documentation/4.2.2/Data/MonitorWMIdata create a directory under that forwarders etc/apps. Then once you have it working on that host copy the directory you have to a deployment server then push it out from there.
You can only collect data via WMI from a Windows version of Splunk, and then forward those to the Linux indexer. The UF (the one you have on Windows) unfortunately does not have a GUI for configuring WMI collection, but it can in fact do the collection as long as the correct configuration files are created and applied.