Getting Data In

How do I get my first log message?

netroworx
New Member

I have setup Universal forwarder on my Windows Server 2016 machine.

I have setup the Universal forwarder credentials to point to my Splunk Cloud.

By default shouldn't I now be getting data from the splunkd.log file?

Regards,

Greg

Tags (3)
0 Karma
1 Solution

skalliger
Motivator

You can always check your metrics.log on your Universal Forwarder installation to check whether data is being sent. Otherwise, you can of course search for index=_internal and also specify host=xyz if you'd like to.

The other Spluk logs are also monitored, not only the splunkd.log. 🙂

View solution in original post

0 Karma

skalliger
Motivator

You can always check your metrics.log on your Universal Forwarder installation to check whether data is being sent. Otherwise, you can of course search for index=_internal and also specify host=xyz if you'd like to.

The other Spluk logs are also monitored, not only the splunkd.log. 🙂

0 Karma

netroworx
New Member

index=_internal shows a number of records.
Some of the records show a host of WIN2016 which is the machine I'm monitoring but when I search on host=WIN2016 I get no results.

0 Karma

netroworx
New Member

Data Summary shows: "Waiting for results..."

0 Karma

netroworx
New Member

If I search:
index=_internal host=WIN2016

I get results so I guess internal events are filtered out by default.

0 Karma

skalliger
Motivator

Glad to hear you're receiving data. 🙂

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...