Author: my2ndhead
Source type(s):
Supported product(s):
App Version: 1.0
Supported CIM Version: >=4.4.0
Supported CIM Data Models:
Eventgen Samples included: Yes
Add-on contains: Search and Parsing-Time configuration
===
Add-on is a partial replacement for Splunk_TA_windows. Focus is on CIM compliancy and performance.
Note 1: Test this add-on first on a separate Search Head before running in production.
Note 2: App is not compatible with Splunk App for Windows Infrastructure due to different eventtype naming
Note 3: App does not include following bin scripts, due to copyright reasons. Run Splunk_TA_windows on Forwarders instead.
Note 4: You can collaborate on the TA at https://github.com/my2ndhead/TA-microsoft-windows
Microsoft KB Documents used for lookups:
Todo: Improve CIM Datamodel compatibility (ongoing)
License: Creative Commons Attribution 4.0 International
https://creativecommons.org/licenses/by/4.0/
First Release, see README.txt
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.