If I want to add/onboard folder access logs from a windows machine to splunk how can I add same?
Answer / Mr.manoj Kumar
To onboard folder access logs from a Windows machine to Splunk, you need to install the Splunk Universal Forwarder on that machine. After setup, you can configure inputs.conf in the $SPLUNK_HOME/etc/apps/splunkforwarder/local directory to forward the folder's logs. You may also use TA-winevents for analyzing Windows event logs.
| Is This Answer Correct ? | 0 Yes | 0 No |
How to start and stop splunk service?
List out some splunk search commands?
What are the types of search modes supported in splunk?
What is splunk tool?
What is the difference between search time and index time field extractions?
What are splunk buckets? Explain the bucket lifecycle?
What is the use of a summary index?
What is sos?
When to use auto_high_volume in splunk?
What are the default fields in Splunk?
Define splunk db connect?
What commands are included in the grouping results category?