hi @Gayatri, Did the windows server available on `Clients` tab on DS? if yes can you query the internal log for that windows server? You can used this query index=_internal host=$windows-server-hostname$ If the log not available need to consider restart the Splunk UF on windows server and if already restart did you enable forwarding on Splunk UF installation?
... View more