Hi @sg17, I see you are installing the Splunk Universal Forwarder at home. I also see that you are having trouble with your most recent reply that you are not seeing any data in the "Data Summary" in the Search and Reporting app. I'm a little confused because you say you are setting up a Splunk Universal Forwarder but a Forwarder comes with the web interface disabled. A Splunk Enterprise instance does come with a web interface enabled, which makes me think that you are running this and not a universal forwarder. You don't need to set an IP for a "receiving indexer" in this solution. If you are just trying to look at logs on your local Windows machine with a default Splunk Enterprise install, it will only ingest its own "Splunk" logs (Which come into the "_internal" index.) If you would like to see more logs on the local machine, please look into installing the Splunk Add-on for Windows app to get more Windows related data. Splunk Add-on for Microsoft Windows Or you can do some one-off's and look at a single log if wanted. Monitor data Do look forward to hearing back from you! V/R, nwuest
... View more