I am just beginning with splunk, so please be patient.
So I have two windows boxes, a dedicated splunk box (with enterprise license) and another windows box as a domain controller.
I've loaded the free version of splunk on the domain controller. Everything looks fine, it indexes the event logs on that device.
Now, i've setup to forward the events to the dedicated splunk box. On the the dedicated splunk box, i see the hostname of the domain controller.
But none of the events are being forwarded... any thoughts?
[Revised on Tue, 13 May 2008 19:30:58 -0700]
So on the domain controller, do i need to indicate what i wish to foward or does it automatically forward everything?