Hi @rcon313, there are two videos that describe how to ingest Windows logs. Anyway, I usually don't start from Add Data, but from Data Inputs, I Use Add-Data when I want to upload logs from a text or csv file. So if you want to take the logs from the machine where Splunk is installed, you have to see in the menu choice [Settings -- Data Inputs] and choose the logs you want: Local Eventlog Collection for Wineventlogs, Files & Directories to read logs e.g. from IIS, Local Performance Monitor to take the performance counters and so on. Please, let me know if my answer solved your need, in this case, please accept it for the other people of Community, otherwise, tell me how can I help you. Ciao and happy splunking. Giuseppe P.S.: Karma Points are appreciated 😉
... View more