Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to get application event logs from each Windows machine with a universal forwarder, but filter some logs based on the server class?

$
0
0
Hi! I have the Splunk Universal Forwarder installed on multiple Windows machines and connected to Splunk Enterprise configured both as receiver and deployment server. I'd like to get the Application event logs from each Windows machine, but filtering some logs basing on the Server Class. From the Web UI, it seems that each Event Log is bound to a certain Server Class. Does it mean that only logs coming from that class are accepted? Any suggestion? Thanks

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>