<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic windows - universal forwarder - localhost in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/windows-universal-forwarder-localhost/m-p/702106#M116144</link>
    <description>&lt;P&gt;I'm trying to let Splunk Enterprise log some creation of a user on the same system as where Splunk is installed.&lt;/P&gt;&lt;P&gt;My Splunk-version is 9.3.1. Alongside with this install, I've installed the latest Universal Forwarder (win) (on localhost 127.0.0.1).&lt;BR /&gt;When installing:&lt;BR /&gt;- I skip the SSL page&lt;BR /&gt;- click "Next"&lt;BR /&gt;- select "Local System"&lt;BR /&gt;- click "Next"&lt;BR /&gt;- check all items under "Windows Log Events"&lt;BR /&gt;- click "Next"&lt;BR /&gt;- generate an admin account and password&lt;BR /&gt;- leave the "Deployment Server"-settings empty&lt;BR /&gt;- enter "127.0.0.1:9997" as Host and port for "Receiving Indexer"&lt;BR /&gt;- finish the installer&lt;/P&gt;&lt;P&gt;Then I create a user (net user /add &amp;lt;user&amp;gt;) in CMD.&lt;BR /&gt;After this step I return to Splunk Search and enter * as search criteria but nothing is found. Even when I enter the username (I added) the software finds nothing.&lt;/P&gt;&lt;P&gt;Can someone tell me what I'm doing wrong or what the issue can be?&lt;BR /&gt;Thanks!&lt;BR /&gt;&lt;BR /&gt;Gerd&lt;/P&gt;</description>
    <pubDate>Wed, 16 Oct 2024 18:41:03 GMT</pubDate>
    <dc:creator>gmoors</dc:creator>
    <dc:date>2024-10-16T18:41:03Z</dc:date>
    <item>
      <title>windows - universal forwarder - localhost</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-universal-forwarder-localhost/m-p/702106#M116144</link>
      <description>&lt;P&gt;I'm trying to let Splunk Enterprise log some creation of a user on the same system as where Splunk is installed.&lt;/P&gt;&lt;P&gt;My Splunk-version is 9.3.1. Alongside with this install, I've installed the latest Universal Forwarder (win) (on localhost 127.0.0.1).&lt;BR /&gt;When installing:&lt;BR /&gt;- I skip the SSL page&lt;BR /&gt;- click "Next"&lt;BR /&gt;- select "Local System"&lt;BR /&gt;- click "Next"&lt;BR /&gt;- check all items under "Windows Log Events"&lt;BR /&gt;- click "Next"&lt;BR /&gt;- generate an admin account and password&lt;BR /&gt;- leave the "Deployment Server"-settings empty&lt;BR /&gt;- enter "127.0.0.1:9997" as Host and port for "Receiving Indexer"&lt;BR /&gt;- finish the installer&lt;/P&gt;&lt;P&gt;Then I create a user (net user /add &amp;lt;user&amp;gt;) in CMD.&lt;BR /&gt;After this step I return to Splunk Search and enter * as search criteria but nothing is found. Even when I enter the username (I added) the software finds nothing.&lt;/P&gt;&lt;P&gt;Can someone tell me what I'm doing wrong or what the issue can be?&lt;BR /&gt;Thanks!&lt;BR /&gt;&lt;BR /&gt;Gerd&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 18:41:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-universal-forwarder-localhost/m-p/702106#M116144</guid>
      <dc:creator>gmoors</dc:creator>
      <dc:date>2024-10-16T18:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: windows - universal forwarder - localhost</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-universal-forwarder-localhost/m-p/702108#M116145</link>
      <description>&lt;P&gt;Never mind...&lt;/P&gt;&lt;P&gt;I've &lt;STRONG&gt;stopped&lt;/STRONG&gt; the universal forwarder-software, waited some second and &lt;STRONG&gt;restarted&lt;/STRONG&gt; the forwarder.&lt;BR /&gt;After this &lt;STRONG&gt;restart&lt;/STRONG&gt; I performed a search (*)&amp;nbsp; and it immediately gave me some results.&lt;/P&gt;&lt;P&gt;I then created a user in the PowerShell, and let Splunk search for the username, resulting in some lines regarding the user.&lt;/P&gt;&lt;P&gt;So... eventually it works as it should...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With kind regards&lt;BR /&gt;Gerd&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 19:16:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-universal-forwarder-localhost/m-p/702108#M116145</guid>
      <dc:creator>gmoors</dc:creator>
      <dc:date>2024-10-16T19:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: windows - universal forwarder - localhost</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-universal-forwarder-localhost/m-p/702109#M116146</link>
      <description>&lt;P&gt;First and foremost - why are you installing a UF when you already have a full Splunk instance? Just add input(s) there.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 19:20:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-universal-forwarder-localhost/m-p/702109#M116146</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-10-16T19:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: windows - universal forwarder - localhost</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-universal-forwarder-localhost/m-p/702111#M116147</link>
      <description>&lt;P&gt;Ooh - that isn't necessary?&lt;BR /&gt;Sorry, I'm new to Splunk.&lt;/P&gt;&lt;P&gt;I was watching some tutorial on Udemy regarding Splunk and was following the guy who did the demo.&lt;BR /&gt;After installing Splunk Enterprise, he started talking about the "universal forwarder" and how to install it. I thought it was part of the whole...&lt;/P&gt;&lt;P&gt;So it wasn't required?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 19:26:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-universal-forwarder-localhost/m-p/702111#M116147</guid>
      <dc:creator>gmoors</dc:creator>
      <dc:date>2024-10-16T19:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: windows - universal forwarder - localhost</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-universal-forwarder-localhost/m-p/702113#M116149</link>
      <description>&lt;P&gt;Universal Forwarder is a lighweight component you typically install on remote machines to - as the name suggests - forward the data to your "main part" of Splunk installation. But if you already have full Splunk instance installed you don't need a UF (there are some border cases when such setup can be useful but makes the whole environment overly complicated).&lt;/P&gt;&lt;P&gt;So if you're just starting with Splunk, it's enough to add local windows event log inputs on the Splunk server.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 19:32:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-universal-forwarder-localhost/m-p/702113#M116149</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-10-16T19:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: windows - universal forwarder - localhost</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-universal-forwarder-localhost/m-p/702114#M116150</link>
      <description>&lt;P&gt;Thanks for the clear info!&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 19:33:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-universal-forwarder-localhost/m-p/702114#M116150</guid>
      <dc:creator>gmoors</dc:creator>
      <dc:date>2024-10-16T19:33:39Z</dc:date>
    </item>
  </channel>
</rss>

