Getting Data In

How to add input stanzas to monitor Windows application, security and system logs via command line?

splunker12er
Motivator

After installing Splunk Universal forwarder in Windows Server ., how to add monitor stanzas for getting windows application , security, system logs via command line ?

>splunk add monitor
0 Karma

DerekKing
Path Finder

Hi,

You can only do part of the job using ./splunk add monitor (on a forwarder). You would still need to manually alter inputs.conf to add the index information.

Why wouldn't you add manually on the UF, or use forwarder management on the indexer to push out configs. ?

Failing that, I think you can tick a checkbox when you install the UF on a windows box to specifically forward Windows Event Logs.

Derek

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...