Getting Data In

Can't find "local event logs" option in splunk

obuobu
Engager

Hey, I installed splunk enterprise free trial on ubuntu server and this is the first time I am using splunk so I am following a video. I am having trouble locating "local event logs" option while adding data to splunk from a universal forwarder in windows server. I want to capture event logs from windows server to see in splunk. Please help me out as soon as possible.

Thank you.Screenshot 2024-04-23 025803.png

Labels (3)

greengrocer92
New Member

Just encountered the same issue.  I'm following allow on a Udemy Splunk course.  The instructor is using Windows and it appears that this option is for local Windows Event logs that one would view in Event Viewer (they're not flat text files).  I'm guessing that the option appears only on Windows, as Ubuntu and MacOS (which I'm using) use flat files for logs rather than Windows events, which I assume are in a dB format that Event Viewer parses.  

0 Karma

kuukudjan
Engager

Kindly repeat the step again  "select the forwarders" then when it comes to selecting the server class dont create a new one just select "existing"  and select the previous one you created and the "local events logs"  will appear. 

nikunj-2386
Engager
- I've encountered the same issue before.
- You can resolve it by following these steps:
- Navigate to "Settings"
- Click on "Data Inputs" Within "Data Inputs," you'll find two sections:
- "Local inputs"
- "Forwarded inputs"
- Choose "Forwarded Inputs"
- Select "Windows Event Logs"

- To add a new configuration, click on the "+ Add new" option next to "Windows Event Logs".
- If you don't see any "Available hosts" at the first "Select Forwarders" stage, try refreshing the page 5-6 times or go back and try adding new again.
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @obuobu ,

let me understand:

  • you have a Splunk Enterprise installed on Ubusntu,
  • then you have Splunk Universal Forwarder installed on a windows machine,
  • you want to see the logs from the Windows machine in Splunk,
  • is it correct?

At first did you configured your Splunk Enterprise Server to receive logs [Settings > Forwardering and Receiving > Receiving]?

Then, did you configured your UF (that I suppose it's installed) to send logs to the Splunk Enterprise Server?

Then did you configured the local inputs locally or using a Deployment Server?

for more infos see the ingestion process at https://docs.splunk.com/Documentation/Splunk/latest/Data/Usingforwardingagents

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...

Stay Connected: Your Guide to October Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...