Splunk® App for Windows Infrastructure

Deploy and Use the Splunk App for Windows Infrastructure

Download manual as PDF

This documentation does not apply to the most recent version of MSApp. Click here for the latest version.
Download topic as PDF

Sample searches and dashboards

This topic lists searches that you can perform to confirm that Windows data has arrived at the indexer.

Search Windows data

To confirm that Windows data is present on the indexer, use the Search app:

1. Log into Splunk Enterprise on the indexer, if you have not already.

2. Load the Search app. In the system bar, select Apps > Search & Reporting. Splunk loads the Search app.

3. Try the following searches to confirm that data is present:

This search confirms that the Splunk Add-on for Windows is sending data to the indexer:

index=windows

This search confirms that the Splunk Add-on for Windows has been installed properly on the deployment client named <host_name>:

index=windows host=<host_name>

Can't find the data?

Try the following:

  • Use Forwarder Management to confirm that the Splunk Add-on for Windows has been deployed to your deployment clients.
  • Confirm that you have enabled Windows inputs in the Splunk Add-on for Windows. If not, make changes and deploy the app again.
  • Refer to the Troubleshooting manual for additional help.
PREVIOUS
Confirm and troubleshoot Windows data collection
  NEXT
Configure Active Directory audit policy

This documentation applies to the following versions of Splunk® App for Windows Infrastructure: 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.2.0, 1.2.1, 1.3.0


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters