Updated inputs.conf file from path "C:\Program Files\SplunkUniversalForwarder\etc\system\default" [monitor://$SPLUNK_HOME\var\log\splunk] index =<Your Indexname> [monitor://$SPLUNK_HOME\var\log\watchdog\watchdog.log*] index =<Your Indexname> Hope this helps
... View more