Deployment Architecture

Help configuring forwarder on Windows 2008R2 for DHCP & RADIUS logs

Sparky70
New Member

I am attempting to add the DHCP and RADIUS logs on a server installed with the Splunk Forwarder.

I have the following configured within C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local\input.conf and restarted the forwarder service.

###### DHCP ######
[monitor://C:\Windows\System32\DHCP]
disabled = false
whitelist = Dhcp*.log
crcSalt = <SOURCE>
sourcetype = Dhcp
alwaysOpenFile = 1

###### RADIUS ######
[monitor://C:\Windows\System32\LogFiles]
disabled = false
whitelist = IN*.log
crcSalt = <SOURCE>
sourcetype = RADIUS
alwaysOpenFile = 1

I cannot see any of that data within Splunk. What am I missing?

0 Karma

phuongnst
New Member

Just this command in input.conf

DHCP

[monitor://C:\Windows\System32\DHCP\Dhcp*.log]
disabled = 0

0 Karma

jstrandman
New Member

You might still have an other inputs.cong file taking precedence over the one you listed above. Check /system/local and any other apps.

0 Karma

satishsdange
Builder

make disabled = 0 & see the results.

0 Karma
Get Updates on the Splunk Community!

Bridging the Gap: Splunk Helps Students Move from Classroom to Career

The Splunk Community is a powerful network of users, educators, and organizations working together to tackle ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...