Getting Data In

Why can't I see any Windows data forwarded from a Win7 machine with a universal forwarder installed and monitoring configured?

alessandromagri
New Member

Hi everybody,
I need to set up a system monitor that collects logon and logout data from some Windows machines (server 2003, server 2008 and Win7).
I've installed the server on an ubuntu server and the Universal Forwarder on the Win7 pc. After the installation of that client I've added the Win7 to the AddData-->forward (in both machine it's set to collect all types of logs) but I can't see any logs about the Win7 machine. Or perhaps I don't know how to see it?

Can anyone help me?

Thanks!

0 Karma

dxmiller
Explorer

I would check your Windows Firewall or 3rd party Firewall/HIPS software to ensure that the Universal Forwarder is permitted to send the log traffic to your Splunk server via TCP 8089. If everything is in order there, I would then check your inputs.conf and outputs.conf files to make sure everything is in order.

0 Karma

alessandromagri
New Member

Now I'm trying to check the inputs.conf and output.conf file but I dont know where to find the right files: in the SplunkUniversalForwarder folder there are many inputs.conf so i dont know the right one to check.
Can someone explane me how I've to do?

0 Karma

alessandromagri
New Member

Thanks for the quick reply.
I've permitt all ports and all protocols for Universal Forwarder on my firewall, but I don't see any log.

But exactly what I've to search to find Windows log?

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...