I am new to a project that utilizes Splunk 7.0.1 Enterprise. I have been monitoring the data on the Enterprise server and noticed that none of the Event Log errors (specifically from Microsoft AppLocker) from my machine are appearing on the server. I have read the manuals and have not discovered anything that will help my situation. Does anyone know were to find a step by step procedure to set my machine up to supply Event Log data to the Splunk server?
Thanks.
Hello bccocek,
Do you have the Windows TA installed? Also, you may want to consider the inputs specified in this previous Answers response.
https://answers.splunk.com/answers/134501/applocker-monitoring.html
Good luck!