Getting Data In

formatting Windows Eventlog in Unix Splunk

sneuser
New Member

Using Splunk indexer (Linux)+ Forwarder v4.2.4 at some Windows Servers. Forwarding is working but cant see details of the forwarded Window Eventlogs. Is there a HowTo that explains more than only adding a source listening to tcp:9997 to become a useable result in Splunk/Ux for Eventlogs?

Tags (2)
0 Karma

Drainy
Champion

Like Ayn says some more details would be useful.
Firstly your inputs.conf detail would explain in more detail how you have it configured (from the universal forwarder (UF).
Anyway, some basics to help-out.
The UF is installed onto your Windows machine and is configured via the inputs.conf and outputs.conf as to what log/file data it reads in and where and how it outputs it.
Assuming you are using all defaults and have just used the setup program for the forwarder to configure the UF it will do the following; output to port 9997 on your indexer and the default target index is main.
On your indexer you should then be able to do a search for;

index=main

and it will display all the contents of that index (by default any searches should happen there anyway on a new install but I thought I'd state it explicitly to help explain).

If nothing is appearing then there could be any number of issues, the target indexer on the UF is wrong, the UF isn't configured to actually forward anything etc.

Something that may be happening which isn't clear is that you are getting events but they appear un-usable to yourself as they are literally the textual content of an event-log. To make the data in events more useful you can perform field extractions to create useful and interesting fields for searching / charting.

Some other bits. I assume you have 9997 defined as a tcp input on the server from your last line, also make sure that any firewall on the system is configured to allow connections.

If you wanted more help checking config detail or event data etc then please feel free to post some examples for us to check over.

0 Karma

Ayn
Legend

Please provide more details. Could you paste some sample events?

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...