Getting Data In

How to forward DVWA logs into my splunk enterprise using spunk universal forwarder?

n_h40
Loves-to-Learn

I am practicing my attacks on the DVWA webserver and I would want to monitor the traffic logs from the DVWA into my splunk enterprise. However, I am unsure of the steps to do so despite following the instructions given of getting data into my splunk enterprise. 

So far, my splunk only monitors the following logs which I do not need.

n_h40_0-1718945627984.png

Additionally, I have added the following for the 'add monitor':

n_h40_0-1718946146293.png

But there is no logs on the apache or anything related to web in my splunk. Therefore, why does my splunk enterprise  captures logs from /var/log syslog only?

 

 

 

Labels (4)
0 Karma
Get Updates on the Splunk Community!

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...