Splunk Search

Can Splunk search client machines System log that has Event ID 7?

tomwahab
New Member

Hello,
Can Splunk search client machines System log that has Event ID 7? We need to scan and retrieve hostnames that have this event ID which is a disk error

Thanks,

0 Karma

starcher
Influencer

You can script the forwarder install with any normal config management tools you have already that can deploy msi installer packages. Then just use a splunk deployment server to control the log collection configuration. Typically done by using the Splunk for Windows TA. However if you have a lot of hosts you may have to consider how big your license is. An alternative would be use a free windows eventlog to syslog tool like Snare for Windows. It can be set to filter what events it sends. Then pickup, index and search those received syslogs.

0 Karma

tomwahab
New Member

thanks, so we would have to install splunk universal forwarder on all our client machines. How big is the software package for the forwarder and is it an easy deployment?

0 Karma

MHibbin
Influencer

install a universal forwarder?

0 Karma

tomwahab
New Member

Thanks, do you know of a tool that can help us?

0 Karma

kristian_kolb
Ultra Champion

Splunk will not scan your network. If you install a forwarder on each machine (or some other agent capable of retrieving logs), you can send them to a Splunk indexer. There you can search through the logs, looking for your events.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...