Getting Data In

splunk forwarder - blue cape security tutorial

benmstl
New Member

Hello Splunk community

in a nutshell my problem is i have set up splunk and a forwarder on a server, added input and output rules respectively. however I am receiving no data from the forwarders to my splunk dashboard.

I am very new to the info sec world and I am following a tutorial on bluecapesecurity.com for setting up a medium home lab. I have a windows 19 server and enterprise client installed. I would love any input on possible solutions. I am sure its going to be something simple or a single setting I missed.

the input.conf file is 

# All Windows Event logs
[monitor://C:\Windows\System32\Winevt\Logs\*.evtx]
disabled = false
index=winevtx

the input.conf file is saved in the:

C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local

I have set up inbound and outbound rules for letting anything from the splunk program through as well as opened the port 9997

Labels (1)
0 Karma

benmstl
New Member

I figured it out. I was just missing the host and guest port numbers in the oracle VM, NAT Network "port forwarding" setting

0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. It's not clearly written but you don't install Splunk server and a UF on the same machine.

But more importantly

2. For windows events you use the wineventlog type inputs. You don't monitor the evtx file.

0 Karma
Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...