How to Forward WSUS Service Logs to Splunk?

Ali Refahiati 20 Reputation points
2024-10-19T10:16:15.92+00:00

Hi,

I have a WSUS server and I'm looking to forward its service logs to Splunk for monitoring and analysis. Could someone help me with the best approach for achieving this?

Specifically:

  1. What steps are required to configure WSUS to export or forward logs to Splunk?
  2. Is there any built-in functionality or tool in WSUS for sending logs to external platforms like Splunk?

Thanks for any guidance or suggestions!

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,289 questions
Microsoft Configuration Manager Updates
Microsoft Configuration Manager Updates
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Updates: Broadly released fixes addressing specific issue(s) or related bug(s). Updates may also include new or modified features (i.e. changing default behavior).
1,061 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Pavel yannara Mirochnitchenko 12,616 Reputation points MVP
    2024-10-31T08:40:07.9966667+00:00

    Be informed what WSUS is depricated. Not sure is there any point anymore to invest into WSUS for you :)

    0 comments No comments

  2. Adam J. Marshall 9,586 Reputation points MVP
    2024-10-31T11:15:22.43+00:00

    Deprecated in terms of end of DEVELOPMENT, yes, but that doesn't mean DEAD or end of SERVICE. There is no change to WSUS in the near and long-term future (10+ years).

    https://www.ajtek.ca/wsus/microsoft-deprecates-wsus-what-does-this-mean-here-is-what-you-need-to-know/

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.