Getting Data In

Splunk Universal Forwarder on Win 2000?

tpaulsen
Contributor

Hallo,

we know it´s not supported officially, but we have some very old Windows 2000 server, that won´t be upgraded before next year, but we need to install Splunk on them. Will the Universal Forwarder work on Windows 2000?

Thank you!

0 Karma
1 Solution

fcorbin
Engager

I think there may be a difference between the forwarder and the configuration I have, but I have yet to figure out what it is, so here's what I know...

I installed Splunk 4.2.1 (Enterprise trial, but since then the trial ran out, so I am running the free license now). Go to Manager > Forwarding and receiving > Forwarding defaults, chose not to store local copy of the events (otherwise I guess this would be an indexer as well). Then go to Configure forwarding and add the host you want to send data to.

good luck...

View solution in original post

0 Karma

mendesjo
Path Finder

I've tested upto 5.0 works..

0 Karma

tpaulsen
Contributor

Yep 4.2.1 works on Win 2000.

0 Karma

tpaulsen
Contributor

fcorbin, thank you, i guess than Splunk> does not try to force you to install on only supported plattforms like other products (BMC....) do...

0 Karma

fcorbin
Engager

I think there may be a difference between the forwarder and the configuration I have, but I have yet to figure out what it is, so here's what I know...

I installed Splunk 4.2.1 (Enterprise trial, but since then the trial ran out, so I am running the free license now). Go to Manager > Forwarding and receiving > Forwarding defaults, chose not to store local copy of the events (otherwise I guess this would be an indexer as well). Then go to Configure forwarding and add the host you want to send data to.

good luck...

0 Karma

tpaulsen
Contributor

Hello, thank you. Did you install the Splunk Forwarder 4.2.1?

0 Karma

fcorbin
Engager

I am new to Splunk so there may be things I haven't seen. FWIW, I installed Splunk as an indexer on a Win 2000 server and it worked fine. I later converted that machine to be a forwarder and it still works fine.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...