If I want to add/onboard folder access logs from a windows machine to splunk how can I add same?
Answer / Mr.manoj Kumar
To onboard folder access logs from a Windows machine to Splunk, you need to install the Splunk Universal Forwarder on that machine. After setup, you can configure inputs.conf in the $SPLUNK_HOME/etc/apps/splunkforwarder/local directory to forward the folder's logs. You may also use TA-winevents for analyzing Windows event logs.
| Is This Answer Correct ? | 0 Yes | 0 No |
Which command is used to the “filtering results” category- explain?
Where to create knowledge objects, dashboards, and reports?
Why use only splunk? Why can’t I go for something that is open source?
What are the components of splunk?
Explain the distinction between splunk and spark?
What is the output lookup command?
How to turn down a peer without affecting any other peer of cluster?
How would you handle/trou/able shoot splunk license violation warning error?
Explain license violation in splunk?
Explain splunk rest api?
How to locate the place where default splunk configuration is stored?
Name companies which are using splunk?