Hey, I installed splunk enterprise free trial on ubuntu server and this is the first time I am using splunk so I am following a video. I am having trouble locating "local event logs" option while adding data to splunk from a universal forwarder in windows server. I want to capture event logs from windows server to see in splunk. Please help me out as soon as possible.
Thank you.
Hi @obuobu ,
let me understand:
At first did you configured your Splunk Enterprise Server to receive logs [Settings > Forwardering and Receiving > Receiving]?
Then, did you configured your UF (that I suppose it's installed) to send logs to the Splunk Enterprise Server?
Then did you configured the local inputs locally or using a Deployment Server?
for more infos see the ingestion process at https://docs.splunk.com/Documentation/Splunk/latest/Data/Usingforwardingagents
Ciao.
Giuseppe