Whenever I attempt to add a remote event log collection I am given this error:
"Splunk failed to fetch the element from the server: error"
Any ideas on what might be causing this?
Thanks
Take a look at this link below. It may give you the details to track this down since the error message has changed from when the below was answered.
You would have a forwarder installed on each server or pull it remotely via WMI.
http://docs.splunk.com/Documentation/Splunk/latest/Data/Windowseventlogsremote
http://docs.splunk.com/Documentation/Splunk/latest/Data/Windowseventlogslocal
Does splunk need to be installed on each machine I want to capture the logs from?