Getting Data In

 


Windows event logs - local

Windows event logs - local

Splunk allows for fast, easy collection of Windows event logs. Whether it's for alerting on security, or reporting on or searching for various event iDs to determine the health of your Windows systems, Splunk's event log collection capabilities make it a snap.

To get local Windows event log data, point Splunk at your Event Log service:

1. From the Home page in Splunk Web, click Add data.

2. Under the To get started... banner, click Windows event logs.

3. Click Next under Collect Windows event logs from this Splunk server.

4. In the "Available Logs" window, click on the event log channels that you want Splunk to monitor.

The log channels will appear in the "Selected Logs" window.

5. Optionally, set the destination index for this source by selecting an index from the Index drop-down box.

6. Click Save.

7. From the Success page, click Search to start searching. You can enter any term that’s in your data, or you can click on a source, source type or host to see data from the events as they come into Splunk.

For more information on getting data from files and directories, see "Monitor Windows event log data" in the Getting Data In manual.

This documentation applies to the following versions of Splunk: 4.2 , 4.2.1 , 4.2.2 , 4.2.3 , 4.2.4 , 4.2.5 , 4.3 , 4.3.1 , 4.3.2 , 4.3.3 , 4.3.4 , 4.3.5 , 4.3.6 , 5.0 , 5.0.1 , 5.0.2 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!