splunk-windows-ta-setup

Render, install, and configure the Splunk Add-on for Microsoft Windows to collect WinEventLog, Perfmon, and WinHostMon data.

36|7|Updated Mar 17, 2026
One-click install
npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-windows-ta-setup
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: splunk-windows-ta-setup
Source: https://github.com/chambear2809/splunk-cisco-skills/tree/main/skills/splunk-windows-ta-setup
Command: npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-windows-ta-setup

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

Administrators need to deploy and configure the Splunk Add-on for Microsoft Windows (Splunk_TA_windows) to collect Windows Event Log, Perfmon, and host-monitoring data, while ensuring proper CIM mappings and placement across forwarders, indexers, and search tiers.

Core Features & Use Cases

  • Renders reviewable inputs.conf overlays for WinEventLog (Security/System/Application, Defender, PowerShell), Perfmon, and WinHostMon stanzas.
  • Creates and places the wineventlog and perfmon indexes and enforces forwarder/DE placement (UF/HF/search-tier) for CIM alignment.
  • Provides a guided workflow for installation, index creation, forwarder rollout via splunk-agent-management-setup, and post-deployment validation.

Quick Start

Install the Splunk Windows TA from Splunkbase, render the inputs and overlays, deploy the app to Windows forwarders, and validate CIM readiness.

Frequently Asked Questions about splunk-windows-ta-setup

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I deploy the Splunk Add-on for Microsoft Windows and map it to CIM?

You deploy the Splunk Windows TA by rendering inputs.conf overlays for WinEventLog, Perfmon, and WinHostMon, creating necessary indexes, rolling out to forwarders, and validating CIM data readiness.

What Windows Event Log channels are configured when deploying Splunk_TA_windows?

Deploying Splunk_TA_windows renders inputs.conf stanzas for Security, System, Application, Defender, and PowerShell WinEventLog channels to ensure comprehensive event collection and CIM alignment.

How do I create wineventlog and perfmon indexes for Splunk Windows forwarders?

This skill creates and places wineventlog and perfmon indexes while enforcing forwarder and search-tier placement to ensure proper CIM alignment across your Splunk deployment.

Does this Splunk Windows TA setup workflow support agent-based forwarder rollout?

Yes, the workflow provides a guided process for forwarder rollout via splunk-agent-management-setup, allowing you to deploy the Splunk Windows TA to Windows forwarders and validate post-deployment data readiness.

Why is my Splunk Windows TA data not mapping to CIM correctly?

Incorrect CIM mapping often results from improper index placement or missing inputs.conf stanzas; this skill enforces forwarder, indexer, and search-tier placement alongside post-deployment validation to ensure data readiness.