Monitoring Splunk

How can I monitor workstation Event Viewer logs?

ericlarsen
Path Finder

Is it possible to ingest individual workstation Event Viewer logs to Splunk? Is installing a UF on each workstation the only way to accomplish it?

Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

its possible to ingest individual workstation event viewer logs to splunk.

detailed documentation can be found here -
http://docs.splunk.com/Documentation/Splunk/6.5.1/Data/MonitorWindowseventlogdata

Per my understanding, Yes, UF should be installed on each workstation.
not sure, but, --- if UF can not be installed, then, some other tools or scripts should collect the event viewer logs and send it a splunk system (not sure how to accomplish this)

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

ericlarsen
Path Finder

Thanks for the quick response. I'm trying to avoid installing a UF on each workstation if possible. I'm hoping someone has come across a feasible alternative.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

maybe, check this one -
Configure Computers to Forward and Collect Events
https://msdn.microsoft.com/en-us/library/cc748890(v=ws.11).aspx

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

Buttercup Games Tutorial Extension - part 9

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games Tutorial Extension - part 8

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Introducing the Splunk Developer Program!

Hey Splunk community! We are excited to announce that Splunk is launching the Splunk Developer Program in ...