Hi folks,
You'll have to excuse my memory lapse here - Splunk forwarder on NT4, installation of - I recall getting an old version of the forwarder to install on NT4 some time back, but the version is no longer available & I don't have the installer - needless to say this is going to be needed in a critical environment where they still run NT4!
Guessing support for NT4 has never been official, so I'm wondering if any of you are using other methods which ARE supported like WMI to retrieve the data?
NT4 EOL was on Dec 31st 2004 which is before "Splunk" was founded. Going back through our available documentation, I am unable to find a UF version which supported that platform, but its possible that a very early version could have. Most definitely, none of our currently available products support it.
NT4 EOL was on Dec 31st 2004 which is before "Splunk" was founded. Going back through our available documentation, I am unable to find a UF version which supported that platform, but its possible that a very early version could have. Most definitely, none of our currently available products support it.
They should use resource on upgrade the NT4 to some later, not time to find forwarder working with it.
It's out of support on every way and a security risk to use.
You should be able to use WMI. Haven't tried it yet, but as long as you can query from WMI, I don't see why it shouldn't work.
So I'm guessing the 4.3 universal forwader on the site is not old enough?
Correct 🙂
Bummer. I dug through as many search engines as i could find looking for maybe a hidden FTP mirror for Splunk downloads. Nothing.
Maybe you could use SNMP to offload the NT4 traffic elsewhere and then Splunk that? I don't know what you would be able to capture for it. Personally, I'd keep searching or maybe post a new question here "Looking for universal forwarder install older than 4.3".