If I want to add/onboard folder access logs from a windows machine to splunk how can I add same?
Answer Posted / Mr.manoj Kumar
To onboard folder access logs from a Windows machine to Splunk, you need to install the Splunk Universal Forwarder on that machine. After setup, you can configure inputs.conf in the $SPLUNK_HOME/etc/apps/splunkforwarder/local directory to forward the folder's logs. You may also use TA-winevents for analyzing Windows event logs.
| Is This Answer Correct ? | 0 Yes | 0 No |
Post New Answer View All Answers