Getting Data In

Universal Forwarder Not sending my windows events log

singhkrmanish76
New Member

Well! i have configured my suplunk server to accept logs on 9997 from remote. And i have configure my universal forwarder to forward logs to my splunk server to 9997 port.
My output.conf file is as:
[tcpout]
defaultGroup = default-autolb-group

[tcpout:default-autolb-group]
server = 10.0.71.250:9997

[tcpout-server://10.0.71.250:9997]

and my input.conf is as:

[default]
host = splunk1-PC

[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]
disabled = 0

[WinEventLog:Application]
disable = false

[WinEventLog:Security]
disable = false

[WinEventLog:System]
disable = false

By doing netstat -n to my splunk server and windows system [universal forwarder] is can see this vice versa

Local Address Foreign Address State
10.0.70.70:51137 10.0.71.250:9997 ESTABLISHED

apache logs are coming from the windows system[universal forwarder] but windows events are not. I am unable to find the exact problem. Kindly help!!

0 Karma

micahkemp
Champion

Your disabled configuration lines appear to have a typo. They should be disabled = 0 (or false), not disable.

You can verify your configuration by running splunk btool inputs list --debug and looking for the ones you attempted to enable to see if they still show disabled = 1 (or true).

0 Karma

ddrillic
Ultra Champion

A cheerful place to start at I can't find my data!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...