<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to edit my universal forwarder monitor stanza to index Active Directory server logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-universal-forwarder-monitor-stanza-to-index/m-p/230772#M44926</link>
    <description>&lt;P&gt;I am trying to monitor the Active Directory Server for logs. I have a universal forwarder installed on a Windows AD Server, and there are logs at the following path: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;%SystemRoot%\System32\Winevt\Logs\
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;How can I monitor it? I have tried the following, but it does not work:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://%SystemRoot%/System32\Winevt\Logs]
targetDC = hqdc06
baseline = false
disabled = 0
index = wineventlog
renderXml=false
Sourcetype = Active Directory
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 16 Nov 2016 21:23:54 GMT</pubDate>
    <dc:creator>anaqvi</dc:creator>
    <dc:date>2016-11-16T21:23:54Z</dc:date>
    <item>
      <title>How to edit my universal forwarder monitor stanza to index Active Directory server logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-universal-forwarder-monitor-stanza-to-index/m-p/230772#M44926</link>
      <description>&lt;P&gt;I am trying to monitor the Active Directory Server for logs. I have a universal forwarder installed on a Windows AD Server, and there are logs at the following path: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;%SystemRoot%\System32\Winevt\Logs\
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;How can I monitor it? I have tried the following, but it does not work:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://%SystemRoot%/System32\Winevt\Logs]
targetDC = hqdc06
baseline = false
disabled = 0
index = wineventlog
renderXml=false
Sourcetype = Active Directory
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 16 Nov 2016 21:23:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-universal-forwarder-monitor-stanza-to-index/m-p/230772#M44926</guid>
      <dc:creator>anaqvi</dc:creator>
      <dc:date>2016-11-16T21:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit my universal forwarder monitor stanza to index Active Directory server logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-universal-forwarder-monitor-stanza-to-index/m-p/230773#M44927</link>
      <description>&lt;P&gt;Hi anaqvi,&lt;BR /&gt;
probably the problem is the slash (/) after %SystemRoot%.&lt;BR /&gt;
Every way, aren't you able to define %SystemRoot%?&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2016 12:15:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-universal-forwarder-monitor-stanza-to-index/m-p/230773#M44927</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2016-11-18T12:15:41Z</dc:date>
    </item>
  </channel>
</rss>

