The Splunk Universal Event Forwarder for Windows cannot collect ETW data. Other solutions can be used such as the NXLog im_etw module shown in this video. We show a demonstration of how you can use the NXLog ETW input module to collect and forward Event Tracing for Windows (ETW) data, write it in JSON structured data format, and forward it to Splunk.
Use NXLog to collect other types of data on Windows and Linux platforms - from Windows EventLog to file-based log collection, file integrity monitoring, and more.
Build a scalable logging infrastructure
The ultimate log collection and centralization solution