Getting Data In

Universal Forwarder - wineventlog

jwilliams
Explorer

Using the Splunk Universal Forwarder for windows.  Does the forwarder identify the data as wineventlog?  How is that set?

Labels (2)
0 Karma
1 Solution

venkatasri
SplunkTrust
SplunkTrust

Hi @jwilliams 

UF ships with Windows add-on which does the collection of winevent logs if the inputs are enabled while installation or can be done later as well.

A detailed post already exist here - https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-collect-basic-Windows-OS-Event-Log-dat...

Splunk docs here - https://docs.splunk.com/Documentation/WindowsAddOn/8.1.2/User/SourcetypesandCIMdatamodelinfo

---

an upvote would be appreciated if this reply helps!

View solution in original post

Tags (1)

venkatasri
SplunkTrust
SplunkTrust

Hi @jwilliams 

UF ships with Windows add-on which does the collection of winevent logs if the inputs are enabled while installation or can be done later as well.

A detailed post already exist here - https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-collect-basic-Windows-OS-Event-Log-dat...

Splunk docs here - https://docs.splunk.com/Documentation/WindowsAddOn/8.1.2/User/SourcetypesandCIMdatamodelinfo

---

an upvote would be appreciated if this reply helps!

Tags (1)
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...