$ 0 0 Hello How do I filter events (Windows event log) on a forwarder? btw how do I install a heavy forwarder? I have Splunk 6.2.3. tnx in advance