Getting Data In

formatting Windows Eventlog in Unix Splunk

sneuser
New Member

Using Splunk indexer (Linux)+ Forwarder v4.2.4 at some Windows Servers. Forwarding is working but cant see details of the forwarded Window Eventlogs. Is there a HowTo that explains more than only adding a source listening to tcp:9997 to become a useable result in Splunk/Ux for Eventlogs?

Tags (2)
0 Karma

Drainy
Champion

Like Ayn says some more details would be useful.
Firstly your inputs.conf detail would explain in more detail how you have it configured (from the universal forwarder (UF).
Anyway, some basics to help-out.
The UF is installed onto your Windows machine and is configured via the inputs.conf and outputs.conf as to what log/file data it reads in and where and how it outputs it.
Assuming you are using all defaults and have just used the setup program for the forwarder to configure the UF it will do the following; output to port 9997 on your indexer and the default target index is main.
On your indexer you should then be able to do a search for;

index=main

and it will display all the contents of that index (by default any searches should happen there anyway on a new install but I thought I'd state it explicitly to help explain).

If nothing is appearing then there could be any number of issues, the target indexer on the UF is wrong, the UF isn't configured to actually forward anything etc.

Something that may be happening which isn't clear is that you are getting events but they appear un-usable to yourself as they are literally the textual content of an event-log. To make the data in events more useful you can perform field extractions to create useful and interesting fields for searching / charting.

Some other bits. I assume you have 9997 defined as a tcp input on the server from your last line, also make sure that any firewall on the system is configured to allow connections.

If you wanted more help checking config detail or event data etc then please feel free to post some examples for us to check over.

0 Karma

Ayn
Legend

Please provide more details. Could you paste some sample events?

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...