I need to collect the security logs from the Windows 7 machine and add the data to Splunk Cloud. I am new to Splunk and am not familiar with the product. Thanks,
There is a topic in the Splunk Cloud documentation that might help you get started: Add data with a forwarder. It includes an example of adding Windows logs.
Hi Chris
I downloaded the Universal Forwarder app and unzipped it. The next step is to move the entire unzipped directory into my forwarder apps directory. (I.e./opt/splunkforwarder/etc/apps/). The example location is not on my desktop. How do I get to the location for me to move the forwarder to the apps directory? Also, do I need to configure my inputs.conf before I move the forwarder to the apps directory?
Note that the Universal Forwarder software is not the same as the Universal Forwarder app that is installed in your Splunk Cloud instance. The app in the product is only to deliver the credentials package that allows a Universal Forwarder installed in your local environment to communicate with your unique instance of Splunk Cloud. You download the credentials and then install them on the machine on which you installed the Universal Forwarder software (that you downloaded from http://www.splunk.com/en_us/download/universal-forwarder.html ).
We are working to make the documentation on this easier to follow, but the topic that ChrisG linked to contains the information that you need.
When you first login to your cloud search head you should see a panel on the left side with a column of large square icons and one of those should say "Universal Forwarder". Click on that app and it will tell you what you need to do.
Hi Woodcock
When I first login to the Splunk Cloud and looked at the panel on the left side, I do not see a Universal Forwarder app listed. I went into the apps section and did a search for Universal Forwarder and nothing came up. I received the message below. Thanks,
There are no configurations of this type. Click the "New" button to create a new configuration.