<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure universal forwarder to forward all Windows events to the Windows index, not main index? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144730#M29554</link>
    <description>&lt;P&gt;Either using the deployment server (Splunk Only) or using something like Puppet or Chef (universal automation tools) will allow you to manage the entire environment from a single point.&lt;/P&gt;</description>
    <pubDate>Tue, 30 Sep 2014 15:18:08 GMT</pubDate>
    <dc:creator>ltrand</dc:creator>
    <dc:date>2014-09-30T15:18:08Z</dc:date>
    <item>
      <title>How to configure universal forwarder to forward all Windows events to the Windows index, not main index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144725#M29549</link>
      <description>&lt;P&gt;We have a new Splunk server. We have installed the universal forwarder on the server and it is currently sending the events to the main index. We would like all Windows events to go to the Windows index. How do I change where these events are go? I would like to do it from the server side if possible.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2014 21:45:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144725#M29549</guid>
      <dc:creator>oldguard911</dc:creator>
      <dc:date>2014-09-29T21:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure universal forwarder to forward all Windows events to the Windows index, not main index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144726#M29550</link>
      <description>&lt;P&gt;Have you tried adding an &lt;CODE&gt;index =[your index]&lt;/CODE&gt; line to the inputs.conf file on your forwarder?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2014 22:50:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144726#M29550</guid>
      <dc:creator>sk314</dc:creator>
      <dc:date>2014-09-29T22:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure universal forwarder to forward all Windows events to the Windows index, not main index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144727#M29551</link>
      <description>&lt;P&gt;No... If I do it that way, every server has to be installed and then configured with the modification. The probability of mistakes on at least some servers is almost 100 percent as we do all of the servers. Is there no way to tell the server to put that traffic in a different index?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 11:44:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144727#M29551</guid>
      <dc:creator>oldguard911</dc:creator>
      <dc:date>2014-09-30T11:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure universal forwarder to forward all Windows events to the Windows index, not main index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144728#M29552</link>
      <description>&lt;P&gt;You configure your forwarder manually or using deployment server?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 11:57:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144728#M29552</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-09-30T11:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure universal forwarder to forward all Windows events to the Windows index, not main index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144729#M29553</link>
      <description>&lt;P&gt;I have been doing it manually, but it sounds like you are suggesting that a deployment server might make the configuration a bit easier? We want to ensure we maintain tight security. I will look into the deployment server to see if that makes the process easier / more consistent. &lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 12:31:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144729#M29553</guid>
      <dc:creator>oldguard911</dc:creator>
      <dc:date>2014-09-30T12:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure universal forwarder to forward all Windows events to the Windows index, not main index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144730#M29554</link>
      <description>&lt;P&gt;Either using the deployment server (Splunk Only) or using something like Puppet or Chef (universal automation tools) will allow you to manage the entire environment from a single point.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 15:18:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144730#M29554</guid>
      <dc:creator>ltrand</dc:creator>
      <dc:date>2014-09-30T15:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure universal forwarder to forward all Windows events to the Windows index, not main index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144731#M29555</link>
      <description>&lt;P&gt;We found an option to modify the props.conf and transforms.conf. We made it work on one Splunk server, but not the second one. The method looks like this on the working server.&lt;/P&gt;

&lt;P&gt;in /opt/splunk/local/props.conf&lt;/P&gt;

&lt;P&gt;add lines&lt;/P&gt;

&lt;P&gt;[WinEventLog:Security]&lt;BR /&gt;
TRANSFFORMS-windows=windows_security&lt;/P&gt;

&lt;P&gt;in /opt/splunk/local/transforms.conf&lt;/P&gt;

&lt;P&gt;[windows_security]&lt;BR /&gt;
REGEX = (.*)&lt;BR /&gt;
FORMAT = &lt;BR /&gt;
DEST_Key =  MetaData:Index&lt;BR /&gt;
WRITE_META = true&lt;/P&gt;

&lt;P&gt;Why would it work on one server and not the other.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:47:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144731#M29555</guid>
      <dc:creator>oldguard911</dc:creator>
      <dc:date>2020-09-28T17:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure universal forwarder to forward all Windows events to the Windows index, not main index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144732#M29556</link>
      <description>&lt;P&gt;And I know why it doesn't work, but I don't know what the line means... &lt;/P&gt;

&lt;P&gt;In /opt/splunk/etc/system/local/props.conf are some lines that do not exist in the server that works. One of those lines is as follows:&lt;/P&gt;

&lt;P&gt;TRANSFORMS = syslog-host&lt;/P&gt;

&lt;P&gt;If I comment this line out, the changes made to redirect the security log start working. If I turn it off, the lines stop working. I am guessing an application we installed made this change, but I don't really understand what the line means. Any one understand why this might be needed?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 20:35:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144732#M29556</guid>
      <dc:creator>oldguard911</dc:creator>
      <dc:date>2014-10-02T20:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure universal forwarder to forward all Windows events to the Windows index, not main index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144733#M29557</link>
      <description>&lt;P&gt;So I think we have the final answer.&lt;/P&gt;

&lt;P&gt;In /opt/splunk/etc/system/local/props.conf before anything else in the file (we had a [localhost] section) add the following lines:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog:Security]
TRANSFORMS-Windows = windows_security

[WinEventLog:System]
TRANSFORMS-Windows = windows_system

[WinEventLog:Application]
TRANSFORMS-Windows = windows_application

[WinEventLog:Setup]
TRANSFORMS-Windows = windows_setup
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Create transforms.conf in /opt/splunk/etc/system/local if it does not exist and add the following lines:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[windows_security]
REGEX = (.*)
FORMAT = windowsLogs
DEST_Key = _MetaData:Index
WRITE_META = true

[windows_system]
REGEX = (.*)
FORMAT = windowsLogs
DEST_Key = _MetaData:Index
WRITE_META = true

[windows_application]
REGEX = (.*)
FORMAT = windowsLogs
DEST_Key = _MetaData:Index
WRITE_META = true

[windows_setup]
REGEX = (.*)
FORMAT = windowsLogs
DEST_Key = _MetaData:Index
WRITE_META = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Make sure you have an index called windowsLogs and then restart the service. All of the logs go to the right location. &lt;/P&gt;

&lt;P&gt;Not sure what created the [localhost] entries in the props.conf file or how critical they are. If any one has any insight on whether what we are doing is good or bad, or why the [localhost] entries might be on one server and not the other, that would be greatly appreciated. For right now it looks like we have what we were hoping for.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 20:58:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-to-forward-all-Windows/m-p/144733#M29557</guid>
      <dc:creator>oldguard911</dc:creator>
      <dc:date>2014-10-02T20:58:24Z</dc:date>
    </item>
  </channel>
</rss>

