Getting Data In

splunk forwarder - blue cape security tutorial

benmstl
New Member

Hello Splunk community

in a nutshell my problem is i have set up splunk and a forwarder on a server, added input and output rules respectively. however I am receiving no data from the forwarders to my splunk dashboard.

I am very new to the info sec world and I am following a tutorial on bluecapesecurity.com for setting up a medium home lab. I have a windows 19 server and enterprise client installed. I would love any input on possible solutions. I am sure its going to be something simple or a single setting I missed.

the input.conf file is 

# All Windows Event logs
[monitor://C:\Windows\System32\Winevt\Logs\*.evtx]
disabled = false
index=winevtx

the input.conf file is saved in the:

C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local

I have set up inbound and outbound rules for letting anything from the splunk program through as well as opened the port 9997

Labels (1)
0 Karma

benmstl
New Member

I figured it out. I was just missing the host and guest port numbers in the oracle VM, NAT Network "port forwarding" setting

0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. It's not clearly written but you don't install Splunk server and a UF on the same machine.

But more importantly

2. For windows events you use the wineventlog type inputs. You don't monitor the evtx file.

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...