About the Splunk App for Windows
Contents
About the Splunk App for Windows
| Important:
If you're looking for documentation on the Splunk Technology Add-on for Windows, which is currently at version 4.6.2, read "About the Splunk Technology Add-on (TA) for Windows." |
The Splunk App for Windows provides data inputs, searches, reports, alerts, and dashboards for Windows management. You can monitor, manage, and troubleshoot Windows operating systems from one place. Included are a set of file, event log, performance monitoring, and other inputs for collecting CPU, disk, I/O, memory, log, configuration, and user data.
You can use the Splunk App for Windows to:
- Get information about who's logged into your system, including information on authorized and unauthorized login attempts and excessively long sessions (through Windows event logs).
- Chart CPU, memory, network and disk utilization across one or more systems (using performance monitoring inputs).
- Learn which Windows Update patches installed successfully on systems, and which did not.
How does it work?
The Splunk App for Windows runs on top of a Splunk instance and gathers various system metrics, including:
- Performance monitoring objects: Processor, System, LogicalDisk, PhysicalDisk, Memory, Network Interface.
- All Windows event logs, including Application, System and Security logs
- Information on Windows update log files.
The app presents this data to you with reports and dashboards to give you full visibility into your Windows systems.
How do I get it?
Download the Splunk App for Windows from Splunkbase.
How do I install it?
First, carefully read the Hardware and platform requirements to understand the network and system resources you should have in place before attempting an installation. Then, learn what data the app collects and what a Splunk App for Windows deployment looks like.
After you familiarize yourself with the system requirements, app capabilities, and sample topology, deploy the app by following the step-by-step installation procedures.
How do I upgrade from a previous version?
The Splunk App for Windows version 5.0 differs significantly from previous versions. If you already run a previous version of the Splunk App for Windows and want to upgrade, read "Upgrade the Splunk App for Windows" for conceptual information, important differences between versions, and specific upgrading instructions.
For information on what's new and what's been fixed from the previous version, as well as any known issues in this version, review the release notes.
This documentation applies to the following versions of WindowsApp: 5.0 View the Article History for its revisions.