Getting Data In

Can someone help me to install and configure a universal forwarder on a Windows 7 machine to forward data to Splunk Cloud?

loctle817
New Member

I need to collect the security logs from the Windows 7 machine and add the data to Splunk Cloud. I am new to Splunk and am not familiar with the product. Thanks,

0 Karma

ChrisG
Splunk Employee
Splunk Employee

There is a topic in the Splunk Cloud documentation that might help you get started: Add data with a forwarder. It includes an example of adding Windows logs.

0 Karma

loctle817
New Member

Hi Chris

I downloaded the Universal Forwarder app and unzipped it. The next step is to move the entire unzipped directory into my forwarder apps directory. (I.e./opt/splunkforwarder/etc/apps/). The example location is not on my desktop. How do I get to the location for me to move the forwarder to the apps directory? Also, do I need to configure my inputs.conf before I move the forwarder to the apps directory?

0 Karma

andrewb_splunk
Splunk Employee
Splunk Employee

Note that the Universal Forwarder software is not the same as the Universal Forwarder app that is installed in your Splunk Cloud instance. The app in the product is only to deliver the credentials package that allows a Universal Forwarder installed in your local environment to communicate with your unique instance of Splunk Cloud. You download the credentials and then install them on the machine on which you installed the Universal Forwarder software (that you downloaded from http://www.splunk.com/en_us/download/universal-forwarder.html ).

We are working to make the documentation on this easier to follow, but the topic that ChrisG linked to contains the information that you need.

woodcock
Esteemed Legend

When you first login to your cloud search head you should see a panel on the left side with a column of large square icons and one of those should say "Universal Forwarder". Click on that app and it will tell you what you need to do.

0 Karma

loctle817
New Member

Hi Woodcock

When I first login to the Splunk Cloud and looked at the panel on the left side, I do not see a Universal Forwarder app listed. I went into the apps section and did a search for Universal Forwarder and nothing came up. I received the message below. Thanks,

There are no configurations of this type. Click the "New" button to create a new configuration.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...