Hi @AL3Z , i don't think that you can install on the same VM both Spunk Enterprise and Splunk Universal Forwarder because they have the same IP and hostname and it's completely unuseful. If you wan...
See more...
Hi @AL3Z , i don't think that you can install on the same VM both Spunk Enterprise and Splunk Universal Forwarder because they have the same IP and hostname and it's completely unuseful. If you want to test the windows logs ingestion from the local machine, you don't need to use the UF and you can use your Splunk instance to create the input (you can do it also by GUI but It's always better to use the Splunk_TA_Windows enabling the interesting inputs). If instead you want to test the connection between an UF and an Indexer, you have to use two different VMs and, on the UF, install the Splunk_TA_Windows enabling the interesting inputs. Ciao. Giuseppe