Splunk® App for Windows Infrastructure (Legacy)

Deploy and Use the Splunk App for Windows Infrastructure

On October 20, 2021, the Splunk App for Windows Infrastructure will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Windows Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for Windows Infrastructure (Legacy). For documentation on the most recent version, go to the latest release.

Platform and hardware requirements

The Splunk App for Windows Infrastructure supports Splunk Enterprise 7.3.x to 8.2.0. All instances of Splunk Enterprise in a Splunk App for Windows Infrastructure deployment must run version 7.3.x to 8.2.0.

Distributed installation of this app

This table provides a quick reference for installing this app onto a distributed deployment of Splunk Enterprise.

If you're using TA-Windows version 6.0.0 or later, you don't need TA_AD and TA_DNS. TA_AD and TA_DNS are merged with TA-Windows version 6.0.0.

Splunk instance type Supported Required Comments
Search Heads Yes Yes Install this app onto all search heads where you require knowledge management.
Indexers No No The Splunk App for Windows Infrastructure does not require installation on indexers, but some components that the app needs to work, such as the Splunk Add-on for Windows, must be installed there. Indexes to which Splunk Add-on for Windows is sending data must be defined on indexers.
Heavy Forwarders No No The Splunk App for Windows Infrastructure does not do anything when you install it on a heavy forwarder, but you can install components that the app needs to function on HFs if you want.
Universal Forwarders No No Use universal forwarders to get the data you need for the app. See the following chapters for instructions on how to configure forwarders to get data (each link goes to the first topic in the chapter):
Light Forwarders No No You can use light forwarders to send data to indexers for the app, but remember that:
  • Light forwarders have been deprecated and could be removed in a future version of Splunk Enterprise.
  • Universal forwarders have better performance than light forwarders.

Distributed deployment compatibility

This table provides a quick reference for the compatibility of this add-on with Splunk distributed deployment features.

Distributed deployment feature Supported Comments
Search Head Clusters Yes You can install this app on a search head cluster. Follow the procedures that this manual outlines to get the data for the app, then install the app on the cluster.
Indexer Clusters Yes Before you start the Splunk App for Windows Infrastructure installation, configure your indexer cluster.
Deployment Server Yes These instructions use a deployment server to set up some of the basic environment for the Splunk App for Windows Infrastructure, including the "send to indexer" package, which tells forwarders that connect to the deployment server to send data to indexers or indexer clusters that you have configured for use with the app.

Hardware requirements

The Splunk App for Windows Infrastructure installs onto a full Splunk Enterprise instance. The app does not install onto a universal forwarder or a light forwarder, because it requires Splunk Web to function fully.

The app has memory, CPU, and disk requirements that are above the standard hardware requirements for the core Splunk Enterprise platform. The added resource requirements depend on how you deploy the app. Be sure to deploy hardware that meets or exceeds the hardware requirements listed in the core Splunk Enterprise documentation.

  • For additional details about supported versions of Windows for Splunk Enterprise, see "System requirements" in the core Splunk Enterprise documentation.
  • For information about estimating hardware requirements for a Splunk deployment, read the following core Splunk Enterprise documentation topics:

Operating system requirements

You can install the Splunk App for Windows Infrastructure on Splunk Enterprise instances that run on many current versions of Windows, including:

  • Windows 7, 8.1, and 10 (64-bit only).
  • Windows Server 2008/2008 R2, Server 2012/2012 R2 (64-bit only) and Server 2016.

The app requires a 64-bit version of Windows because of App Key Value Store.

You can also install the app on a non-Windows Splunk Enterprise instance to display Windows data coming from external Windows sources:

  • Linux

Neither Splunk nor the Splunk App for Windows Infrastructure runs on:

  • Windows 95, 98, or Me
  • Windows NT Workstation or Server 3.1, 3.5, or 4.0
  • Windows 2000 Workstation or Server

What browsers does the Splunk App for Windows Infrastructure support?

The Splunk App for Windows Infrastructure supports all browsers that the current version of Splunk Enterprise supports.

What are the other prerequisites?

If you're using TA-Windows version 6.0.0 or later, you don't need TA_AD and TA_DNS. TA_AD and TA_DNS are merged with TA-Windows version 6.0.0.

The Splunk Add-on for Windows version 7.0.0 or version 8.0.0

Version Compatibility Table

Compatible TA-Windows version Compatible Winfra version Compatible Splunk platform version Compatible Windows Server version Compatible SA-LDAP version
6.0.0 2.0.1 7.2.x to 7.3.x 2012, 2012 R2, 2016, 2019 3.0.1
7.0.0 2.0.1 7.2.x to 8.1.0 2012, 2012 R2, 2016, 2019 3.0.1
7.0.0 2.0.2 7.3.x to 8.2.0 2012, 2012 R2, 2016, 2019 3.0.2
8.0.0 2.0.2 7.3.x to 8.2.0 2012, 2012 R2, 2016, 2019 3.0.2

To collect data from the Windows and Exchange servers in your environment, you need the Splunk Technology Add-on for Windows version 7.0.0 or 8.0.0.

This add-on installs into the universal forwarder that you install on the Windows servers from which you want to collect Windows data. It also installs on search heads that run the Splunk App for Windows Infrastructure to provide knowledge objects to the app. Optionally, it also installs onto all indexers in the central Splunk App for Windows instance for data collection (on Windows hosts) and to add knowledge for extractions.

You can download the Splunk Add-on for Windows from Splunkbase.

The Splunk Add-ons for Microsoft Active Directory 1.0.0 or later and Windows DNS v1.0.1 or later

The suite of Splunk Add-ons for Active Directory must be installed on universal forwarders and search heads in the Windows deployment.

You can download the Splunk Add-ons for Microsoft Active Directory and Windows DNS from Splunkbase.

If you're using TA-Windows version 6.0.0 or later, you don't need TA_AD and TA_DNS. TA_AD and TA_DNS are merged with TA-Windows version 6.0.0.

The Splunk Supporting Add-on for Active Directory (SA-LDAPsearch) version 3.0.2

The Splunk Supporting Add-on for Active Directory (SA-LDAPsearch) version 3.0.2 must be installed on the same instances of Splunk Enterprise that the Splunk App for Windows Infrastructure resides.

You can download the Splunk Supporting Add-on for Active Directory from Splunk Apps.

A proficient understanding of distributed Splunk deployments

If you plan for your Splunk App for Windows Infrastructure deployment to monitor a large number of Active Directory servers, or even a small number, you must understand how distributed Splunk works. You must understand how the instance of Splunk Enterprise that hosts the app interacts with the universal forwarders that send data to the app. You must also understand what you need to do to increase search and indexing performance to make the app run faster. Read the following core Splunk topics for additional information:

Time and patience

The Splunk App for Windows Infrastructure is an advanced application that has several components that must be configured correctly in order for the app to run. Depending on the size of your Windows network, it can take a while to get a Splunk App for Windows Infrastructure deployment up and running correctly.

You will spend time procuring hardware, identifying servers you want to monitor, installing the app and its included add-ons, tweaking configurations, and troubleshooting any issues you come across.

The setup instructions in this manual span several chapters and uses the Splunk Enterprise deployment server for automation wherever possible. Still, expect to spend a minimum of 4 to 8 hours on the project, and longer if you have a large deployment.

If your deployment is large or complex, Splunk is here to help. You can contact Professional Services for assistance if you have an Enterprise support contract.

Do not install and configure the Splunk App for Windows Infrastructure and the Splunk App for Microsoft Exchange on the same search head

The Splunk App for Windows Infrastructure and the Splunk App for Microsoft Exchange should not be installed on the same search head, as both apps contain identical knowledge objects that may cause a conflict when installed on the same search head deployment. If you need dashboards and functionalities for both apps on the same search head, then install only the Splunk App for Microsoft Exchange as it covers all dashboards and functionalities of the Splunk App for Windows Infrastructure.

Last modified on 20 May, 2021
How to get support and find more information about Splunk Enterprise   Permissions checklist

This documentation applies to the following versions of Splunk® App for Windows Infrastructure (Legacy): 2.0.2


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters