Getting Data In

formatting Windows Eventlog in Unix Splunk

sneuser
New Member

Using Splunk indexer (Linux)+ Forwarder v4.2.4 at some Windows Servers. Forwarding is working but cant see details of the forwarded Window Eventlogs. Is there a HowTo that explains more than only adding a source listening to tcp:9997 to become a useable result in Splunk/Ux for Eventlogs?

Tags (2)
0 Karma

Drainy
Champion

Like Ayn says some more details would be useful.
Firstly your inputs.conf detail would explain in more detail how you have it configured (from the universal forwarder (UF).
Anyway, some basics to help-out.
The UF is installed onto your Windows machine and is configured via the inputs.conf and outputs.conf as to what log/file data it reads in and where and how it outputs it.
Assuming you are using all defaults and have just used the setup program for the forwarder to configure the UF it will do the following; output to port 9997 on your indexer and the default target index is main.
On your indexer you should then be able to do a search for;

index=main

and it will display all the contents of that index (by default any searches should happen there anyway on a new install but I thought I'd state it explicitly to help explain).

If nothing is appearing then there could be any number of issues, the target indexer on the UF is wrong, the UF isn't configured to actually forward anything etc.

Something that may be happening which isn't clear is that you are getting events but they appear un-usable to yourself as they are literally the textual content of an event-log. To make the data in events more useful you can perform field extractions to create useful and interesting fields for searching / charting.

Some other bits. I assume you have 9997 defined as a tcp input on the server from your last line, also make sure that any firewall on the system is configured to allow connections.

If you wanted more help checking config detail or event data etc then please feel free to post some examples for us to check over.

0 Karma

Ayn
Legend

Please provide more details. Could you paste some sample events?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...