Getting Data In

formatting Windows Eventlog in Unix Splunk

sneuser
New Member

Using Splunk indexer (Linux)+ Forwarder v4.2.4 at some Windows Servers. Forwarding is working but cant see details of the forwarded Window Eventlogs. Is there a HowTo that explains more than only adding a source listening to tcp:9997 to become a useable result in Splunk/Ux for Eventlogs?

Tags (2)
0 Karma

Drainy
Champion

Like Ayn says some more details would be useful.
Firstly your inputs.conf detail would explain in more detail how you have it configured (from the universal forwarder (UF).
Anyway, some basics to help-out.
The UF is installed onto your Windows machine and is configured via the inputs.conf and outputs.conf as to what log/file data it reads in and where and how it outputs it.
Assuming you are using all defaults and have just used the setup program for the forwarder to configure the UF it will do the following; output to port 9997 on your indexer and the default target index is main.
On your indexer you should then be able to do a search for;

index=main

and it will display all the contents of that index (by default any searches should happen there anyway on a new install but I thought I'd state it explicitly to help explain).

If nothing is appearing then there could be any number of issues, the target indexer on the UF is wrong, the UF isn't configured to actually forward anything etc.

Something that may be happening which isn't clear is that you are getting events but they appear un-usable to yourself as they are literally the textual content of an event-log. To make the data in events more useful you can perform field extractions to create useful and interesting fields for searching / charting.

Some other bits. I assume you have 9997 defined as a tcp input on the server from your last line, also make sure that any firewall on the system is configured to allow connections.

If you wanted more help checking config detail or event data etc then please feel free to post some examples for us to check over.

0 Karma

Ayn
Legend

Please provide more details. Could you paste some sample events?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...