Getting Data In

Show remote windows event log/events using universal forwarder


Hi All,

I am new to Splunk. We want to build a POC to capture windows event logs, specific event IDs from a remote machine (where we have installed the universal forwarder) and cature the data on another machine (where we installed the solunk web). Both installations have been done using "local system user accounts". Can you please provide me a step by step documentation or an example perhaps to achieve this.

Thanks in advance.


Tags (1)
0 Karma


These errors seem to be caused by a generally improper Splunk setup rather than specific errors in the Windows log monitoring. As with all troubleshooting, you should go through the setup step by step to make sure things work. It's kind of broad to ask for the complete solution to your situation in one single answer.

0 Karma


I have already gone through these links. We already took a decision of going with universal forwarder instead of WMI as this POC is intended to expand to trapping BizTalk transactions at a later point of time. Due to the perfomance criterias outlined we want to go for forwarder approach. Can you please help me in understanding (or any documentation) where and how i can see the transactions on the splunkweb. I have been trying to view the responses on deployment monitor but it shows "no data found - inspect". Also forwarding connections show the same message.

0 Karma
Get Updates on the Splunk Community!

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...

Platform Highlights | January 2023 Newsletter

 January 2023Peace on Earth and Peace of Mind With Business ResilienceAll organizations can start the new year ...