Getting Data In

Indexing evt files in a distributed environment

MHibbin
Influencer

All,

Just a quick query on monitoring exported evt files...

We are looking to use linux for our Indexers, however as some of our data will come from Windows based machines, we initially were looking at importing the data from WMI (installationg of a Universal Forwarder is not an option). However, as the remote Windows machines are not connected to the AD (only use local authentication), we are looking at using a Windows based forwarder, as it has access to the Windows processors for evt files. Is there any restriction on the type of forwarder used (e.g. Universal, of Light-weight)? - I wasn't sure of the level of event processing from the forwarder, before passing it to the Linux based Indexer?.

I know I will have to use automatic sourcetyping, which will allow Splunk to detect the evt/evtx file extension and process it correctly.

Any thoughts welcome.

Thanks in advance,

MHibbin

Runals
Motivator

I'm confused - you can or can't install a local Splunk agent? If you are able to use one then it doesn't matter that your indexers are Linux or even if they aren't in the same domain. If you can't use a Splunk UF you probably can't use a Snare agent either but is another option. The data format sort of sucks once it is in Splunk (tab delimited and multiple spaces make field definition a pain) but at least it would be in Splunk. If your Windows machines are Win7/Win2k8 you could look into native event forwarding to another Win2k8 server and put a Splunk agent on it. I haven't ever tried that and don't know if there are limitations given your AD situation.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...