Splunk® Enterprise

Getting Data In

Download manual as PDF

Download topic as PDF

How to get Windows data into your Splunk deployment

You can collect the following Windows data with Splunk software:

Since only Windows machines provide this data, only the Windows version of Splunk Enterprise can get the data. Other operating systems cannot collect Windows data directly. You can send Windows data from Windows machines to Splunk Enterprise instances that do not run Windows. If you have Splunk Cloud and want to monitor these inputs, the Splunk Universal Forwarder is your only option.

How Splunk Enterprise interacts with Windows modular and scripted inputs on start-up and shutdown

When you configure a scripted or modular Windows data input in Splunk Enterprise, the splunkd service sends a signal to the input to begin collecting the data. Similarly, when you shut Splunk Enterprise down cleanly, the service sends a different signal to the inputs to tell them to stop collecting data, clean up, and exit.

The following table lists the control messages that the splunkd service sends to modular and scripted Windows inputs during start-up and shutdown.

Control messages (signals) sent by the splunkd service to Windows modular and scripted inputs
Start-up Shutdown
CreateProcess CTRL_BREAK_EVENT

Use Splunk Web to collect Windows data

Nearly all Windows inputs let you use the Splunk Web interface to get the data. The exception is the MonitorNoHandle input, which you must set up with a configuration file.

  1. Log into your Splunk deployment.
  2. Click Settings in the upper right corner, then click Data inputs. The Data inputs page appears.
  3. Find the Windows input that you want to add in the list of available inputs by clicking Add new in the Actions column for the input.
  4. Follow the instructions in the subsequent pages for the input type you selected.
  5. Click Save. In most cases, data collection begins immediately.

Use configuration files to collect Windows data

In cases where you cannot use Splunk Web to configure Windows inputs, such as when you use a universal forwarder to collect the data, you must use configuration files (the universal forwarder installer on Windows lets you configure some Windows inputs at installation time.)

Configuration files offer more control over Splunk Web in many cases. Some inputs can only be configured this way.

  1. Open a command prompt or PowerShell window,
  2. Change to the %SPLUNK_HOME%\etc\system\local directory.
  3. Edit inputs.conf in this directory. You might need to create this file.
  4. Add inputs to the inputs.conf file by defining input stanzas.
  5. Save the file and close it.
  6. Restart the Splunk instance. The software reloads the configuration files and begins collecting data based on the new configuration.
PREVIOUS
Monitoring Windows data with Splunk Enterprise
  NEXT
Considerations for deciding how to monitor remote Windows data

This documentation applies to the following versions of Splunk® Enterprise: 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11, 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 6.6.10, 6.6.11, 6.6.12, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.3.0


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters