- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
I have a windows machine with UF installed on that machine. How can I configure my Universal forwarder to ingest windows performance monitoring logs into SPLUNK. Our Windows Source server is located in different location SPLUNK should be getting performance data from. Any help would be greatly appreciated. Thank you!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @SplunkDash ,
I don't know why, but the form adds a part to the address.
remove all the chars after 742 in the url address.
or go in apps.splunk.com and search Splunk Add-On for Windows.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Have you tried installing the Splunk Add-on for Microsoft Windows (https://splunkbase.splunk.com/app/742) on that UF?
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @richgalloway ,
Thank you so much for your quick response. Regarding the Add On, I haven't, but you link is not working.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @SplunkDash ,
please use this: https://splunkbase.splunk.com/app/742
remember to copy the inputs.conf file in a local folder (to create) and to enable (disabled = 0) the inputs you need because, by default, all the inputs are disabled.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you so much for your quick response. The link you sent to me is not working and getting blank screen. When you get a chance, please send the name of the Add On, so I can search for it in Splunk base. Thank you again!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @SplunkDash ,
I don't know why, but the form adds a part to the address.
remove all the chars after 742 in the url address.
or go in apps.splunk.com and search Splunk Add-On for Windows.
Ciao.
Giuseppe
