Hi,
I'm using splunk recently.
How can I configure "windows events" (example login access) to send them to splunk? I need a Universal forwarder? On splunk, which configuration should I do?
thanks in advance
Stefano
I have configured the Universal Forwarder, but I any case the data that the server splunk collect from the server are too old. ??!!?
When I try to set the remote event log on splunk, I have always the same error "in handler 'win-wmi-enum-eventlogs' unable to get wmi classes from host"
Can u help me?
Hi Stefano,
you have various possibilities depending on your security requirements and network infrastructure : using a Windows local forwarder, WMI, ...
See http://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorWindowsdata
/dd