Getting Data In

Is it possible to configure the universal forwarder to forward all Windows event logs without needing to put in every single log by hand?

kpers
Path Finder

For some time now I have been using Splunk to log all the basic Windows event logs such as App, Security, Setup, System, and Forwarded Events, but I cannot find a simple way to grab all the "Applications and Services Logs" since as far as I can tell, there is no way to use wildcards in the config to achieve this.

I personally do not want to hand type all the possible logs under this directory for each server and was hoping someone had a simple answer to this?

0 Karma

jkat54
SplunkTrust
SplunkTrust

As you've found there isnt a wildcard method. To make matters worse if you create custom windows event logs using your own applications, you have to add these to the windows event log viewer at least once, before you can consume them with Splunk. It has to do with some windows intricacies though and Splunk isn't to blame for that.

Another method is to write a script to dump the logs to file, but I would suggest many of the "Applications and Services Logs" that you have are A. Not enabled, B. Not useful to your end goal, and C. perhaps a waste of splunk licensing to index them.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...