There is no need to install Splunk Enterprise and Universal Forwarder on the same server. It can be done, but requires special effort with little gain. Splunk Enterprise is capable of everything the UF does. 1) Put the UF on the syslog server and SE on separate servers. 2) The receiver address is that of Splunk. It's the server that will receive data from the UF. 3) Which Microsoft add-on? There are several and most are not needed. 4) Configure syslog to save events to disk files. Configure the UF (in inputs.conf) to monitor those disk files.
... View more