Getting Data In

Why can't we get Windows event logs to our Splunk 4.2.2 instance using a 6.2.1 universal forwarder?

05500
New Member

Our environment
Splunk version 4.2.2
Universal forwarder version 6.2.1

We have already used Splunk from a few years ago, but we can't get windows event logs for Windows 2008 or 2012, so we installed universal forwarder on each windows 2008/2012 with firewall setting.
However we can't still receive any windows event logs.

Is this because of different Splunk versions? or Firewall settings made mistakes?
If you have any advice, please let us know.

0 Karma
1 Solution

HiroshiSatoh
Champion

HiroshiSatoh
Champion

from here

http://www.splunk.com/page/previous_releases

6.x forwarders (universal/light/heavy) are backwards compatible down to 5.0.x indexers.

http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/Compatibilitybetweenforwardersandindexe...

05500
New Member

Thank you for your support.
As you advised, we could transfer syslog data using universal forwarder.

0 Karma

05500
New Member

What site can we get older universal forwarder?

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...