Getting Data In

Why can't I see any Windows data forwarded from a Win7 machine with a universal forwarder installed and monitoring configured?

alessandromagri
New Member

Hi everybody,
I need to set up a system monitor that collects logon and logout data from some Windows machines (server 2003, server 2008 and Win7).
I've installed the server on an ubuntu server and the Universal Forwarder on the Win7 pc. After the installation of that client I've added the Win7 to the AddData-->forward (in both machine it's set to collect all types of logs) but I can't see any logs about the Win7 machine. Or perhaps I don't know how to see it?

Can anyone help me?

Thanks!

0 Karma

dxmiller
Explorer

I would check your Windows Firewall or 3rd party Firewall/HIPS software to ensure that the Universal Forwarder is permitted to send the log traffic to your Splunk server via TCP 8089. If everything is in order there, I would then check your inputs.conf and outputs.conf files to make sure everything is in order.

0 Karma

alessandromagri
New Member

Now I'm trying to check the inputs.conf and output.conf file but I dont know where to find the right files: in the SplunkUniversalForwarder folder there are many inputs.conf so i dont know the right one to check.
Can someone explane me how I've to do?

0 Karma

alessandromagri
New Member

Thanks for the quick reply.
I've permitt all ports and all protocols for Universal Forwarder on my firewall, but I don't see any log.

But exactly what I've to search to find Windows log?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...