<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I make the sourcetype WinEventLog:Application active? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-make-the-sourcetype-WinEventLog-Application-active/m-p/373368#M67683</link>
    <description>&lt;P&gt;abl-bccwprhyb01 07/19/2017 22:17:10 sqleventlog WinEventLog:Application EPS INACTIVE (7-30days)&lt;/P&gt;

&lt;P&gt;Source type WinEventLog:Application is inactive for sqlevent index&lt;/P&gt;

&lt;P&gt;in error and warnings it showing no result found. that's why I am not able to check exactly what I need to check and where and how can I make this source type WinEventLog:Application active. Please help&lt;/P&gt;</description>
    <pubDate>Fri, 18 Aug 2017 05:14:40 GMT</pubDate>
    <dc:creator>asorot</dc:creator>
    <dc:date>2017-08-18T05:14:40Z</dc:date>
    <item>
      <title>How can I make the sourcetype WinEventLog:Application active?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-make-the-sourcetype-WinEventLog-Application-active/m-p/373368#M67683</link>
      <description>&lt;P&gt;abl-bccwprhyb01 07/19/2017 22:17:10 sqleventlog WinEventLog:Application EPS INACTIVE (7-30days)&lt;/P&gt;

&lt;P&gt;Source type WinEventLog:Application is inactive for sqlevent index&lt;/P&gt;

&lt;P&gt;in error and warnings it showing no result found. that's why I am not able to check exactly what I need to check and where and how can I make this source type WinEventLog:Application active. Please help&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2017 05:14:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-make-the-sourcetype-WinEventLog-Application-active/m-p/373368#M67683</guid>
      <dc:creator>asorot</dc:creator>
      <dc:date>2017-08-18T05:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: How can I make the sourcetype WinEventLog:Application active?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-make-the-sourcetype-WinEventLog-Application-active/m-p/373369#M67684</link>
      <description>&lt;P&gt;in your inputs.conf add the stanza as shown below : &lt;/P&gt;

&lt;P&gt;[WinEventLog://Application]&lt;BR /&gt;
disabled = 0&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jul 2018 17:04:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-make-the-sourcetype-WinEventLog-Application-active/m-p/373369#M67684</guid>
      <dc:creator>joechakkola1</dc:creator>
      <dc:date>2018-07-29T17:04:09Z</dc:date>
    </item>
  </channel>
</rss>

