Example configuration to send events from Contrast's Universal Forwarder to Grafana Loki
-
Updated
Aug 31, 2026 - Go Template
Example configuration to send events from Contrast's Universal Forwarder to Grafana Loki
Using Google GRR Rapid Response to analyze remote clients.
Docker-based Splunk lab simulating a Deployment Server and Universal Forwarders for hands-on configuration management and data forwarding practice.
Configured a Splunk Universal Forwarder on a remote Ubuntu system to forward syslog and authentication logs to a central Splunk indexer. Includes setup steps, search queries, and incident response observations. Part of the 30-Day SOC Challenge.
Splunk monitoring lab: Windows Event Log, Sysmon and Linux telemetry onboarding, forwarding-state validation, SPL analysis, reports and dashboards — documented from sanitized screenshot evidence.
Splunk Cloud SIEM lab documenting Windows log ingestion, Sysmon forwarding, and detection searches for brute-force and PowerShell misuse.
Windows endpoint monitoring lab using Sysmon, Splunk Universal Forwarder, and Splunk Enterprise.
To associate your repository with the universal-forwarder topic, visit your repo's landing page and select "manage topics."