I recently upgraded a workstation to Win10 Enterprise. I installed the Splunk universal forwarder, however I am not collecting any data from the workstation at the indexer. I believe it has something to do with certificates, but I am not very well versed in the product. I'm afraid the documentation isn't helping much either.
So the forwarder worked on a previous version of Windows but is not working after upgrading to Win10?
Can you check your outputs.conf
under SPLUNK_HOME\etc\system\local
and verify its pointing to the correct indexer(s)?
If it is, you should then go to SPLUNK_HOME\etc\var\log\splunk
and open up splunkd.log
and see if its complaining about anything