Getting Data In

How do I get my first log message?

netroworx
New Member

I have setup Universal forwarder on my Windows Server 2016 machine.

I have setup the Universal forwarder credentials to point to my Splunk Cloud.

By default shouldn't I now be getting data from the splunkd.log file?

Regards,

Greg

Tags (3)
0 Karma
1 Solution

skalliger
Motivator

You can always check your metrics.log on your Universal Forwarder installation to check whether data is being sent. Otherwise, you can of course search for index=_internal and also specify host=xyz if you'd like to.

The other Spluk logs are also monitored, not only the splunkd.log. 🙂

View solution in original post

0 Karma

skalliger
Motivator

You can always check your metrics.log on your Universal Forwarder installation to check whether data is being sent. Otherwise, you can of course search for index=_internal and also specify host=xyz if you'd like to.

The other Spluk logs are also monitored, not only the splunkd.log. 🙂

0 Karma

netroworx
New Member

index=_internal shows a number of records.
Some of the records show a host of WIN2016 which is the machine I'm monitoring but when I search on host=WIN2016 I get no results.

0 Karma

netroworx
New Member

Data Summary shows: "Waiting for results..."

0 Karma

netroworx
New Member

If I search:
index=_internal host=WIN2016

I get results so I guess internal events are filtered out by default.

0 Karma

skalliger
Motivator

Glad to hear you're receiving data. 🙂

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...