- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Configure SYSLog on a Windows Server
jesusgalloEMC
Explorer
01-30-2018
05:23 PM
Hello,
my question might be dumb but it is worth to ask,
On a Windows Servers, how do i configure to send the authentication.log to a Splunk heavy forwarder?
is this the same to say "I need to configure the syslog to be sent to the heavy forwarder?"
Thank you!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
damode
Motivator
01-30-2018
08:00 PM
- Install a universal forwarder on your windows server
- During the installation, put Heavy Forwarder's IP in the Receiving Indexer field (and deployment server IP if you have one)
- Configure monitor input stanza in inputs.conf to point to the authentication.log
- restart the universal forwarder.
