I am practicing my attacks on the DVWA webserver and I would want to monitor the traffic logs from the DVWA into my splunk enterprise. However, I am unsure of the steps to do so despite following the instructions given of getting data into my splunk enterprise.
So far, my splunk only monitors the following logs which I do not need.
Additionally, I have added the following for the 'add monitor':
But there is no logs on the apache or anything related to web in my splunk. Therefore, why does my splunk enterprise captures logs from /var/log syslog only?