This is a follow up for a conversation I had with Splunk engineers a year ago at SplunkLive! The conversation was about using Microsoft's Eventing 6.0 (native to Windows) which would eliminate the need to use Splunk's forwarder agent on all production devices. (Depending on the environment not using Splunk's forwarder can have governance, security and performance advantages. Another is being able to pull information Splunk's forwarder can't using WMI.
The Splunk engineers I spoke to at the time were not familiar with Evneting and could not comment. Not using Splink's forwarder has some intriguing advantages such as the ability to pull data Splunk's forwarder cannot.
I have plans to use Splunk in the U.S. Cyber Challenge and was looking for a way to automate the deployment of the publishing rules. I'm wondering is Splunk has made any progress in using Eventing?
Using PowerShell the initial Event Publication configuration could be distributed easily to hundreds of servers and to perform any updates. Trevor Sullivan has a post providing the details. If you have any can think of any enchantments Microsoft or the PowerShell team would like to hear from you just post your suggestions.