I'm using splunk recently.
How can I configure "windows events" (example login access) to send them to splunk? I need a Universal forwarder? On splunk, which configuration should I do?
thanks in advance
I have configured the Universal Forwarder, but I any case the data that the server splunk collect from the server are too old. ??!!?
When I try to set the remote event log on splunk, I have always the same error "in handler 'win-wmi-enum-eventlogs' unable to get wmi classes from host"