Getting Data In

Can't receive logs from AD W2019

Am
Explorer

Hi,

We have installed and configured Splunk in a Linux machine with the objective of receiving data from an AD in a Windows Server 2019. After installing the "Splunk Universal Forwarder" and following the steps in the documentation we see the following output with the netstat command: "splunk:8089 SYN_SENT".
The Splunk installed in the Linux machine has the "Splunk Add-on for Microsoft Windows" and both services (the UF in the Windows machine too) were restarted after adding it.
Then, when the "Data Inputs - Windows Event Logs" option is selected we can see the following error: "Select Forwarders This feature is not available with your installed set of licenses"
Therefore, we can't receive any logs.

Are we missing something here?

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...