For the training, we are going to install the universal forwarder in the default configuration. Our goal is to send Windows logs to Splunk.

Launch the setup

Read the Licence Agreement

Accept the Licence Agreement

Select "an on-premises Splunk Enterprise instance" because we have to install Splunk on an on-premise server.

Once again, we use the default configuration. Maybe in your company, you will use a service account to run the Universal Forwarder.