Splunk Enterprise

Do I need a universal forwarder

rcon313
Explorer

Hi guys,

I am very new to Splunk and this is only my first week using it. What I am wanting to do is view the performance logs of my own local machine and then put it into a dashboard. It would also be good to be able to get the number of times I have logged into my laptop if that is possible. The questions is, Do I need to use a universal forwarder to be able to do all this ? I am not sure, from what I have read online the universal forwarder is used for remote machines but because its local would I need to use one. I can imagine this being a very noobie question but need the help if someone is able to.

 

Thank You

Labels (1)
0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @rcon313 

you can install Splunk enterpirse  on you localhost for colleting logs and creating dashboard.

Splunk enterpirse work as single package which can ingest the data , store the data , and searhch the data for your localhost, you can use this software for 60 days free trail .


link to download

https://www.splunk.com/en_us/download/splunk-enterprise.html

after steup you can access splunk on http://localhost:8000/ 

 

stpes to moniotr your local system data

SanjayReddy_0-1633064793051.png

 

SanjayReddy_1-1633064812464.png

 

SanjayReddy_2-1633064829680.png

 

SanjayReddy_3-1633064849280.png

 



0 Karma

rcon313
Explorer

Thank you very much 

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

@rcon313 

if you found reply is helpfull, please accept it as solution 

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...