Getting Data In

I can't find "Local event log collection" on my Splunk enterprise on my MacBook.

daniel99
New Member

I am trying to configure Splunk to ingest only application, system and security logs from my local machine. But I can't find "Local event log collection" on my Splunk enterprise on my MacBook. 

But on my former laptop, which was a windows OS, I could find the "Local event log collection" option in the data input section. 

Please how can I go about this?

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Are you trying to collect macOS logs or Windows logs?

If you are trying those from macOS, there are logd input method which you could try. Unfortunately there is some issues with current splunk versions with it (see https://community.splunk.com/t5/Getting-Data-In/Wrong-parameters-on-macOS-and-logd-input/td-p/702261). Until splunk fix this you must use e.g. TA for nix or use your own scripts to use "log show" command with correct parameters.

r. Ismo

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @daniel99 ,

did you installed the Splunk_TA_Windows ( https://splunkbase.splunk.com/app/742 ) on your Splunk?

Ciao.

Giuseppe

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...