Splunk® App for Windows Infrastructure (Legacy)

Deploy and Use the Splunk App for Windows Infrastructure

On October 20, 2021, the Splunk App for Windows Infrastructure will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Windows Dashboards and Reports.

Deploy the Splunk Add-on for Windows

This topic discusses deploying the Splunk Add-on for Windows to the deployment clients that you have configured to connect to the deployment server. Once you deploy the add-on, the deployment clients begin collecting Windows data and sending it to the indexer.

Place the add-on in the deployment apps directory on the deployment server

The deployment server must be made aware of the new app. You do this by placing it in the deployment apps directory:

  1. Open a command prompt on the deployment server/indexer.
  2. Copy the entire Splunk Add-on for Windows folder from its current location to the deployment apps directory:
  3. > Copy-Item -Path C:\Downloads\Splunk_TA_Windows -Destination "C:\Program Files\Splunk\etc\deployment-apps\Splunk_TA_Windows" -Recurse
  4. Tell the deployment server to reload its deployment configuration.
  5. > cd \Program Files\Splunk\bin
    > .\splunk reload deploy-server
  6. From a web browser, log into Splunk Enterprise on the deployment server.
  7. In the system bar, select Settings > Forwarder Management.
  8. Click the Apps tab. You should see the Splunk_TA_Windows add-on in the list of apps.
  9. In the "Splunk_TA_Windows" add-on entry in the list, click Edit. Splunk Enterprise loads the "Edit App: Splunk_TA_Windows" page.
  10. Click the gray "+" sign under "Server Classes".
  11. Select the "Universal Forwarders" server class you created during initial setup.. Splunk Enterprise displays the deployment clients that will receive the app in the lower half of the page. You should see the deployment client that you set up previously.
  12. Click Save. Splunk Enterprise saves the configuration, returns you to the Forwarder Management menu, and deploys the Splunk_TA_Windows app to the deployment client.
  13. Exch 31 DeployApps TAWindows.png

What's next?

You have now deployed the Splunk Add-on for Windows onto your deployment client. In the future, you can use this procedure to deploy the add-on to additional clients.

Next, you will confirm that Windows data is coming into the indexer.

Last modified on 22 June, 2020
Download and configure the Splunk Add-on for Windows   Confirm and troubleshoot Windows data collection

This documentation applies to the following versions of Splunk® App for Windows Infrastructure (Legacy): 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.5.0, 1.5.1, 1.5.2, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters