Hi Splunk Community I am completely new on splunk. I somehow managed to deploy the splunk Universal Forwarder on many linux nodes and few windows systems. I am able to view the /var/log/secure and /var/log/message that are getting indexed and the windows security event log on the created index. I want a dashboard that shows information of the below :- 1. Number of Hosts where splunk forwarder is deployed (linux and windows separate). 2. Successfull and failed login. 3. Alert when root is logged in linux and Administrator login in windows.
... View more