Getting Data In

How to only forward Windows Security logs

sventura15
Explorer

Hi,

I would like to forward only successful and failed Windows login attempts from my Windows 2008 Server to my RHEL forwarder. How do I go about configuring this?

My thanks in advance

sventura15
Explorer

another question, this props and transforms file, are they supposed to be edited in the default directory (C:\Program Files\Splunk\etc\system\default), or are the files supposed to be moved to the C:\Program Files\Splunk\etc\system\local and then edited ?

0 Karma

sventura15
Explorer

after doing this, and restarting splunk, is there anything else I have to do or just look for logs to show up on the receiveing end ?

Thanks

0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...