Getting Data In

Can't receive logs from AD W2019



We have installed and configured Splunk in a Linux machine with the objective of receiving data from an AD in a Windows Server 2019. After installing the "Splunk Universal Forwarder" and following the steps in the documentation we see the following output with the netstat command: "splunk:8089 SYN_SENT".
The Splunk installed in the Linux machine has the "Splunk Add-on for Microsoft Windows" and both services (the UF in the Windows machine too) were restarted after adding it.
Then, when the "Data Inputs - Windows Event Logs" option is selected we can see the following error: "Select Forwarders This feature is not available with your installed set of licenses"
Therefore, we can't receive any logs.

Are we missing something here?

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...