The Hortonworks Community Connection is now live. A completely rebuilt Q&A forum, Knowledge Base, Code Hub and more, backed by the experts in the industry.

You will be redirected here in 10 seconds. If your are not redirected, click here to visit the new site.

The legacy Hortonworks Forum is now closed. You can view a read-only version of the former site by clicking here. The site will be taken offline on January 31,2016

Sqoop Forum

windows event logs

  • #46677
    Nathan Weinrich

    I am trying determine the best practice for getting windows event logs into hdfs, via flume, without installing something on the event log source servers. I’ve unearthed several possible options, but none seem like a standard solution to what i would think an extremely common scenario.

    1. put an agent on the event log source server – too invasive, would impact existing server etc
    2. move logs into a directory and use File Spool Directory agent – this would be an extra copy step and additional overhead, and would likely require another process on the log source server.
    3. Configure port forwarding via winrm quickconfig. I didn’t really see much doc on this, and do not know how invasive it is to the event log source server and so am not confident as an option.
    4. Configure network shares that would allow for an Exec agent to read the logs. I guess windows shares on each event log source server and then Samba on my linux/flume box could work?
    5. Other?


  • Author
  • #49336
    Robert Molina

    Hi Nathan,
    It looks like you covered most of them. Based on your requirements you mentioned, it looks like option 4 should be able to work.


The forum ‘Sqoop’ is closed to new topics and replies.

Support from the Experts

A HDP Support Subscription connects you experts with deep experience running Apache Hadoop in production, at-scale on the most demanding workloads.

Enterprise Support »

Become HDP Certified

Real world training designed by the core architects of Hadoop. Scenario-based training courses are available in-classroom or online from anywhere in the world

Training »

Hortonworks Data Platform
The Hortonworks Data Platform is a 100% open source distribution of Apache Hadoop that is truly enterprise grade having been built, tested and hardened with enterprise rigor.
Get started with Sandbox
Hortonworks Sandbox is a self-contained virtual machine with Apache Hadoop pre-configured alongside a set of hands-on, step-by-step Hadoop tutorials.
Modern Data Architecture
Tackle the challenges of big data. Hadoop integrates with existing EDW, RDBMS and MPP systems to deliver lower cost, higher capacity infrastructure.