Getting Data In

Indexing evt files in a distributed environment

MHibbin
Influencer

All,

Just a quick query on monitoring exported evt files...

We are looking to use linux for our Indexers, however as some of our data will come from Windows based machines, we initially were looking at importing the data from WMI (installationg of a Universal Forwarder is not an option). However, as the remote Windows machines are not connected to the AD (only use local authentication), we are looking at using a Windows based forwarder, as it has access to the Windows processors for evt files. Is there any restriction on the type of forwarder used (e.g. Universal, of Light-weight)? - I wasn't sure of the level of event processing from the forwarder, before passing it to the Linux based Indexer?.

I know I will have to use automatic sourcetyping, which will allow Splunk to detect the evt/evtx file extension and process it correctly.

Any thoughts welcome.

Thanks in advance,

MHibbin

Runals
Motivator

I'm confused - you can or can't install a local Splunk agent? If you are able to use one then it doesn't matter that your indexers are Linux or even if they aren't in the same domain. If you can't use a Splunk UF you probably can't use a Snare agent either but is another option. The data format sort of sucks once it is in Splunk (tab delimited and multiple spaces make field definition a pain) but at least it would be in Splunk. If your Windows machines are Win7/Win2k8 you could look into native event forwarding to another Win2k8 server and put a Splunk agent on it. I haven't ever tried that and don't know if there are limitations given your AD situation.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...