All Apps and Add-ons

Is it possible to have different apps/configurations with Splunk add-on for Windows?

rocarril
Engager

The app collects windows events, hostmon, regmon, and perfmon.

I'd like to have a modular approach where:
1) All systems are assigned to collect windows events
2) Select systems are assigned to collect hostmon, regmon, and/or perfmon

I tried creating separate folders (apps) with different inputs.conf files, but it seems the "main" app (windows events) is overriding the others.

Tags (1)
0 Karma

FrankVl
Ultra Champion

Rather than copying the entire TA and making modifications to multiple copies of the TA (and keeping both updated with new releases etc.), I'd rather suggest to install the TA just as is, without any active inputs.conf. And create separate small apps that contain the inputs.conf that you need.

When deploying on universal forwarders, I think you don't even need the TA itself at all on the forwarders?

A similar question has been discussed recently in the following thread: https://answers.splunk.com/answers/620404/deployment-server-how-to-handle-a-single-add-on-wi.html

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi rocarril,
yes, yoo can create two TAs, called e.g. TA_Windows_all and TA_Windows_perfmon, copying the same TA_Windows and customizing each one for your needs.
After you need to create two different ServerClasses for your systems putting the correct servers in each one.

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...