Admin Manual

 


Authentication

MonitorWare

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

MonitorWare

For IIS or Exchange message tracking logs that can't be read through Snare or Samba, you can set up MonitorWare and Splunk to index and search your Windows logs in about 15 minutes. If you only need to index NT event logs, Snare is more expedient. You do not need MonitorWare if you can use Samba mounts, nor do you need it to send log4j data.



Video Demo

Splunk Ninja Episode 001 shows a complete, live Monitorware / Splunk integration in less than five minutes.


Installation

Add a RuleSet

TCP or UDP?

Add Service

When you click Play, MonitorWare Agent should begin forwarding your data to the remote syslog or Splunk server you've configured.


External Links

This documentation applies to the following versions of Splunk: 2.1 , 2.2 , 2.2.1 , 2.2.3 , 2.2.6 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!