<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk forwarder - blue cape security tutorial in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/splunk-forwarder-blue-cape-security-tutorial/m-p/694478#M115391</link>
    <description>&lt;P&gt;1. It's not clearly written but you don't install Splunk server and a UF on the same machine.&lt;/P&gt;&lt;P&gt;But more importantly&lt;/P&gt;&lt;P&gt;2. For windows events you use the wineventlog type inputs. You don't monitor the evtx file.&lt;/P&gt;</description>
    <pubDate>Sat, 27 Jul 2024 13:52:08 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2024-07-27T13:52:08Z</dc:date>
    <item>
      <title>splunk forwarder - blue cape security tutorial</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-forwarder-blue-cape-security-tutorial/m-p/694477#M115390</link>
      <description>&lt;P&gt;Hello Splunk community&lt;/P&gt;&lt;P&gt;in a nutshell my problem is i have set up splunk and a forwarder on a server, added input and output rules respectively. however I am receiving no data from the forwarders to my splunk dashboard.&lt;/P&gt;&lt;P&gt;I am very new to the info sec world and I am following a tutorial on bluecapesecurity.com for setting up a medium home lab. I have a windows 19 server and enterprise client installed. I would love any input on possible solutions. I am sure its going to be something simple or a single setting I missed.&lt;/P&gt;&lt;P&gt;the input.conf file is&amp;nbsp;&lt;/P&gt;&lt;P&gt;# All Windows Event logs&lt;BR /&gt;[monitor://C:\Windows\System32\Winevt\Logs\*.evtx]&lt;BR /&gt;disabled = false&lt;BR /&gt;index=winevtx&lt;/P&gt;&lt;P&gt;the input.conf file is saved in the:&lt;/P&gt;&lt;P&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local&lt;/P&gt;&lt;P&gt;I have set up inbound and outbound rules for letting anything from the splunk program through as well as opened the port 9997&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jul 2024 13:17:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-forwarder-blue-cape-security-tutorial/m-p/694477#M115390</guid>
      <dc:creator>benmstl</dc:creator>
      <dc:date>2024-07-27T13:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: splunk forwarder - blue cape security tutorial</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-forwarder-blue-cape-security-tutorial/m-p/694478#M115391</link>
      <description>&lt;P&gt;1. It's not clearly written but you don't install Splunk server and a UF on the same machine.&lt;/P&gt;&lt;P&gt;But more importantly&lt;/P&gt;&lt;P&gt;2. For windows events you use the wineventlog type inputs. You don't monitor the evtx file.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jul 2024 13:52:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-forwarder-blue-cape-security-tutorial/m-p/694478#M115391</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-27T13:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: splunk forwarder - blue cape security tutorial</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-forwarder-blue-cape-security-tutorial/m-p/694479#M115392</link>
      <description>&lt;P&gt;I figured it out. I was just missing the host and guest port numbers in the oracle VM, NAT Network "port forwarding" setting&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jul 2024 14:09:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-forwarder-blue-cape-security-tutorial/m-p/694479#M115392</guid>
      <dc:creator>benmstl</dc:creator>
      <dc:date>2024-07-27T14:09:45Z</dc:date>
    </item>
  </channel>
</rss>

