Hey, I installed splunk enterprise free trial on ubuntu server and this is the first time I am using splunk so I am following a video. I am having trouble locating "local event logs" option while adding data to splunk from a universal forwarder in windows server. I want to capture event logs from windows server to see in splunk. Please help me out as soon as possible.
Thank you.
Just encountered the same issue. I'm following allow on a Udemy Splunk course. The instructor is using Windows and it appears that this option is for local Windows Event logs that one would view in Event Viewer (they're not flat text files). I'm guessing that the option appears only on Windows, as Ubuntu and MacOS (which I'm using) use flat files for logs rather than Windows events, which I assume are in a dB format that Event Viewer parses.
Kindly repeat the step again "select the forwarders" then when it comes to selecting the server class dont create a new one just select "existing" and select the previous one you created and the "local events logs" will appear.
- I've encountered the same issue before.
- You can resolve it by following these steps:
- Navigate to "Settings"
- Click on "Data Inputs" Within "Data Inputs," you'll find two sections:
- "Local inputs"
- "Forwarded inputs"
- Choose "Forwarded Inputs"
- Select "Windows Event Logs"
- To add a new configuration, click on the "+ Add new" option next to "Windows Event Logs".
- If you don't see any "Available hosts" at the first "Select Forwarders" stage, try refreshing the page 5-6 times or go back and try adding new again.
Hi @obuobu ,
let me understand:
At first did you configured your Splunk Enterprise Server to receive logs [Settings > Forwardering and Receiving > Receiving]?
Then, did you configured your UF (that I suppose it's installed) to send logs to the Splunk Enterprise Server?
Then did you configured the local inputs locally or using a Deployment Server?
for more infos see the ingestion process at https://docs.splunk.com/Documentation/Splunk/latest/Data/Usingforwardingagents
Ciao.
Giuseppe