Getting Data In

Is there a version of Splunk Universal Forwarder that is compatible with NT4?

sentiaglobal
New Member

Hi folks,

You'll have to excuse my memory lapse here - Splunk forwarder on NT4, installation of - I recall getting an old version of the forwarder to install on NT4 some time back, but the version is no longer available & I don't have the installer - needless to say this is going to be needed in a critical environment where they still run NT4!

Guessing support for NT4 has never been official, so I'm wondering if any of you are using other methods which ARE supported like WMI to retrieve the data?

0 Karma
1 Solution

jcrabb_splunk
Splunk Employee
Splunk Employee

NT4 EOL was on Dec 31st 2004 which is before "Splunk" was founded. Going back through our available documentation, I am unable to find a UF version which supported that platform, but its possible that a very early version could have. Most definitely, none of our currently available products support it.

Jacob
Sr. Technical Support Engineer

View solution in original post

jcrabb_splunk
Splunk Employee
Splunk Employee

NT4 EOL was on Dec 31st 2004 which is before "Splunk" was founded. Going back through our available documentation, I am unable to find a UF version which supported that platform, but its possible that a very early version could have. Most definitely, none of our currently available products support it.

Jacob
Sr. Technical Support Engineer

lakromani
Builder

They should use resource on upgrade the NT4 to some later, not time to find forwarder working with it.
It's out of support on every way and a security risk to use.

0 Karma

kungfu71186
New Member

You should be able to use WMI. Haven't tried it yet, but as long as you can query from WMI, I don't see why it shouldn't work.

0 Karma

JDukeSplunk
Builder

So I'm guessing the 4.3 universal forwader on the site is not old enough?

https://www.splunk.com/page/download_track?file=4.3/windows/splunkforwarder-4.3-115073-x86-release.m...

0 Karma

sentiaglobal
New Member

Correct 🙂

0 Karma

JDukeSplunk
Builder

Bummer. I dug through as many search engines as i could find looking for maybe a hidden FTP mirror for Splunk downloads. Nothing.

Maybe you could use SNMP to offload the NT4 traffic elsewhere and then Splunk that? I don't know what you would be able to capture for it. Personally, I'd keep searching or maybe post a new question here "Looking for universal forwarder install older than 4.3".

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...