From the course: Integrating Splunk with Microsoft Purview
Unlock this course with a free trial
Join today to access over 25,300 courses taught by industry experts.
Monitor local machine logs with Splunk - Splunk Tutorial
From the course: Integrating Splunk with Microsoft Purview
Monitor local machine logs with Splunk
- [Instructor] In this video, we would use the monitor console to find out how machine logs are being captured on your local machine. To get started, let's go to settings, add data, use the monitor console to capture information by configuring the local event logs. You configure the instance to monitor the local Windows event log channels where installed applications, services, and system processes send data. From the first window, you can select available items or available event logs. We have so many event logs here to capture. You need to select which of the event logs you would love to capture. Once you click on them, it appears on the right side, which allows you to know that these are the selected items you would love to capture their event logs. Items like application, general logs, hardware event, internet explorer, key management, security, setup, and system. So we would be capturing the event logs for those items. Click next. Here you have to configure your input settings…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.