@seph thanks for replying... if I recall correctly, the.method to use splunk woild be to config inouts.conf to run a powershell command and write to a log file, then pass the log file contents to the splunk indexes. Ex: I can write arbitrary powershell (
some is OS agnostic) and capture the output. I can push the powershell code out to my nodes using a few different mechs. I am looking at kolide (thank you, it looks great) and am trying to disprove it's usage as I stated earlier I'm trying to be
http://boringtechnology.club... my company is heavily invest in splunk baseline and now I have a learning curve. Trying to separate the two may be an argument in use case availability. This is why I was focused on this.