Hello, thank you for your quick answer, I have used this documentation: https://docs.splunk.com/Documentation/SplunkCloud/9.0.2209/Data/Monitorwindowseventlogdata https://docs.splunk.com/Documentation/MSApp/2.0.4/MSInfra/InstallauniversalforwarderoneachWindowshost I then configured the conf file inputs.conf : # Windows platform specific input processor. [WinEventLog://Application] disabled = 0 [WinEventLog://Security] disabled = 0 [WinEventLog://System] disabled = 0 Then I restarted the service I installed Splunk Add-on for Microsoft Windows from the SplunkCloud platform where we make requests (I call it the console) What do you mean by, "Have you installed the Universal Forwarder application from your Splunk Cloud search head on your UF?" Thank you
... View more