<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarding windows event viewer logs to Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124092#M25596</link>
    <description>&lt;P&gt;I am getting the logs by installing splunk universal forwarder on my server and by modifying inputs.conf as shown below&lt;/P&gt;

&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;but can somebody please tell me, that i need only event ids 6276 and 6278 only, not all events?&lt;/P&gt;</description>
    <pubDate>Wed, 29 Nov 2017 14:57:23 GMT</pubDate>
    <dc:creator>koolvasco</dc:creator>
    <dc:date>2017-11-29T14:57:23Z</dc:date>
    <item>
      <title>Forwarding windows event viewer logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124085#M25589</link>
      <description>&lt;P&gt;I have installed Splunk on a Linux box and is listening for incoming on 9997. Our linux boxes send its syslog to it and work fine. &lt;BR /&gt;
The Windows boxes however do not send any event viewer logs. I installed SplunkForwarder on it and followed the prompts where I entered the Receiver server and port 9997. Also restarted the splunk service just in case. &lt;BR /&gt;
What additional configurations are to be done to ensure Event Viewer logs/AD monitoring start to populate my Splunk sitting on the Linux box. &lt;BR /&gt;
I'm able to telnet to 9997 from Windows to Linux so it is not an access issue. &lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2014 22:19:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124085#M25589</guid>
      <dc:creator>kkossery</dc:creator>
      <dc:date>2014-01-23T22:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding windows event viewer logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124086#M25590</link>
      <description>&lt;P&gt;Did you read the following topics in the docs?&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/ConsiderationsfordecidinghowtomonitorWindowsdata"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/ConsiderationsfordecidinghowtomonitorWindowsdata&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorWindowsdata"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorWindowsdata&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2014 22:28:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124086#M25590</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2014-01-23T22:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding windows event viewer logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124087#M25591</link>
      <description>&lt;P&gt;Thank you for these links. However, I see some things are missing here,&lt;/P&gt;

&lt;P&gt;Configure remote event log monitoring&lt;BR /&gt;
 1. Click Settings in the upper right-hand corner of Splunk Web.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Under Data, click Data Inputs.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Click Remote event log collections.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Click Add new to add an input.&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;I do not see Remote event log collections under Data Inputs. Do I need to activate something on my Linux box Splunk to show this.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2014 00:30:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124087#M25591</guid>
      <dc:creator>kkossery</dc:creator>
      <dc:date>2014-01-24T00:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding windows event viewer logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124088#M25592</link>
      <description>&lt;P&gt;i have tried doing this again on another Windows box and I'm unable to install the program that will forward logs to the Splunk box. Can someone help?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2014 18:39:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124088#M25592</guid>
      <dc:creator>kkossery</dc:creator>
      <dc:date>2014-01-27T18:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding windows event viewer logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124089#M25593</link>
      <description>&lt;P&gt;More details than "unable to install" would help.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2014 19:34:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124089#M25593</guid>
      <dc:creator>dglinder</dc:creator>
      <dc:date>2014-01-27T19:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding windows event viewer logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124090#M25594</link>
      <description>&lt;P&gt;When you installed the Splunk Universal Forwarder on the Windows system, did you check the appropriate check-boxes on the "Enable Windows Inputs" page near the end of the install?&lt;/P&gt;

&lt;P&gt;If not, you'll need to enable them on the Windows systems "inputs.conf" file - link:&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.1/Data/Monitorwindowsdata#Use_inputs.conf_to_configure_event_log_monitoring"&gt;see this page for details&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;TL;DR notes:&lt;BR /&gt;
Edit the inputs.conf on the Windows system (usually &lt;EM&gt;C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf&lt;/EM&gt;) and add these lines:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;[WinEventLog://Application]&lt;/P&gt;

&lt;P&gt;disabled = 0 &lt;/P&gt;

&lt;P&gt;[WinEventLog://Security]&lt;/P&gt;

&lt;P&gt;disabled = 0 &lt;/P&gt;

&lt;P&gt;[WinEventLog://System]&lt;/P&gt;

&lt;P&gt;disabled = 0 &lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;You'll need to restart the SplunkUniversalForwarder service on the Windows system.  Your Splunk index should start receiving these events.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2014 19:36:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124090#M25594</guid>
      <dc:creator>dglinder</dc:creator>
      <dc:date>2014-01-27T19:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding windows event viewer logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124091#M25595</link>
      <description>&lt;P&gt;Installing on a different Windows box worked with the above settings. Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2014 13:27:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124091#M25595</guid>
      <dc:creator>kkossery</dc:creator>
      <dc:date>2014-01-28T13:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding windows event viewer logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124092#M25596</link>
      <description>&lt;P&gt;I am getting the logs by installing splunk universal forwarder on my server and by modifying inputs.conf as shown below&lt;/P&gt;

&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;but can somebody please tell me, that i need only event ids 6276 and 6278 only, not all events?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2017 14:57:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/124092#M25596</guid>
      <dc:creator>koolvasco</dc:creator>
      <dc:date>2017-11-29T14:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding windows event viewer logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/561732#M100068</link>
      <description>&lt;P&gt;Hey, I am wondoring How Can I send Log files from linux to windows? I downloaded splunk in windows and forwarder in linux. I can telnet 9997 from linux to windows but I don't know how to send a files. can anybody help me with it?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 17:34:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-windows-event-viewer-logs-to-Splunk/m-p/561732#M100068</guid>
      <dc:creator>patel1515</dc:creator>
      <dc:date>2021-08-02T17:34:19Z</dc:date>
    </item>
  </channel>
</rss>

