All Apps and Add-ons

Splunk App for Windows Infrastructure not Detecting All feeds

scc00
Contributor

The forwarder and app has been installed and configured as shown in the instructions. The apps configuration settings cannot detect all the logs currently coming into Splunk. It detects some of the data inputs but not all. Is there a specific location I need to check to update this? Or am I missing some configuration step? The forwarder is monitoring the relevant location where all the logs sit.

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

Have you checked the eventtypes? The app relies heavily on them and by default these don't always point to the correct indexes where your data is located.

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...