NETWORK ADMINISTRATIONSwindows dns serverWindows server

Splunk add on for MS windows | Getting Windows data into splunk

Link to download ‘The Splunk Add-on for Windows’: –
https://splunkbase.splunk.com/app/742/#/details

Step by step demonstration of how to get Windows data into Splunk Enterprise.

The Splunk Add-on for Windows allows a Splunk software administrator to collect:

CPU, disk, I/O, memory, log, configuration, and user data with data inputs.

Active Directory and Domain Name Server debug logs from Windows hosts that act as domain controllers for a supported version of a Windows Server. You must configure Active Directory audit policy since Active Directory does not log certain events by default.

Domain Name Server debug logs from Windows hosts that run a Windows DNS Server. Windows DNS Server does not log certain events by default, and you must enable debug logging.

source

by Learn A Logic

windows server dns forwarder

18 thoughts on “Splunk add on for MS windows | Getting Windows data into splunk

  • Hi Team, could you please present a video which shows how to integrate AppD with Splunk?

  • Thank you bro… Your videos are most useful in peak times .please do a video on Datamodel Acceleration.

  • Thanks for the Video, Could you please Explain Complete Step-By-Step For Getting All Emails Logs From Microsoft Exchange Server 2019, So can get all Email Fails, Receiving Rejections Logs etc… on Splunk, Thanks in advance

  • Thank you very much. This video helped me a lot to get myself started in Splunk

  • Sir. I need search query for different devices

  • Good video! any chance you could go through setting up Splunk to monitor O365?

  • Please make a video on how to downgrade an addon ( example Splunk Addon for windows like above)

  • since i installed the addon i can't log on splunk in https :/

  • hi
    Have configurued it
    but getting too many logs
    How can I define specific logs?
    Please help guys

  • Could you please create few videos on splunk Enterprise Security..

Comments are closed.