Getting Data In

splunk forwarder - blue cape security tutorial

benmstl
New Member

Hello Splunk community

in a nutshell my problem is i have set up splunk and a forwarder on a server, added input and output rules respectively. however I am receiving no data from the forwarders to my splunk dashboard.

I am very new to the info sec world and I am following a tutorial on bluecapesecurity.com for setting up a medium home lab. I have a windows 19 server and enterprise client installed. I would love any input on possible solutions. I am sure its going to be something simple or a single setting I missed.

the input.conf file is 

# All Windows Event logs
[monitor://C:\Windows\System32\Winevt\Logs\*.evtx]
disabled = false
index=winevtx

the input.conf file is saved in the:

C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local

I have set up inbound and outbound rules for letting anything from the splunk program through as well as opened the port 9997

Labels (1)
0 Karma

benmstl
New Member

I figured it out. I was just missing the host and guest port numbers in the oracle VM, NAT Network "port forwarding" setting

0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. It's not clearly written but you don't install Splunk server and a UF on the same machine.

But more importantly

2. For windows events you use the wineventlog type inputs. You don't monitor the evtx file.

0 Karma
Get Updates on the Splunk Community!

Video | Welcome Back to Smartness, Pedro

Remember Splunk Community member, Pedro Borges? If you tuned into Episode 2 of our Smartness interview series, ...

Detector Best Practices: Static Thresholds

Introduction In observability monitoring, static thresholds are used to monitor fixed, known values within ...

Expert Tips from Splunk Education, Observability in Action, Plus More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...