Hi All,
I am new to Splunk. We want to build a POC to capture windows event logs, specific event IDs from a remote machine (where we have installed the universal forwarder) and cature the data on another machine (where we installed the solunk web). Both installations have been done using "local system user accounts". Can you please provide me a step by step documentation or an example perhaps to achieve this.
Thanks in advance.
Regards
Anshu
You'll want to read through these first. There are a couple of options.
Local:
http://docs.splunk.com/Documentation/Splunk/latest/Data/Windowseventlogslocal
Remote:
http://docs.splunk.com/Documentation/Splunk/latest/Data/Windowseventlogsremote
These errors seem to be caused by a generally improper Splunk setup rather than specific errors in the Windows log monitoring. As with all troubleshooting, you should go through the setup step by step to make sure things work. It's kind of broad to ask for the complete solution to your situation in one single answer.
I have already gone through these links. We already took a decision of going with universal forwarder instead of WMI as this POC is intended to expand to trapping BizTalk transactions at a later point of time. Due to the perfomance criterias outlined we want to go for forwarder approach. Can you please help me in understanding (or any documentation) where and how i can see the transactions on the splunkweb. I have been trying to view the responses on deployment monitor but it shows "no data found - inspect". Also forwarding connections show the same message.