<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Event Forwarding in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Forwarding/m-p/548952#M91237</link>
    <description>&lt;P&gt;I can't help with the transform.&amp;nbsp; Try posting a new question with the transform in it.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Apr 2021 12:57:04 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-04-22T12:57:04Z</dc:date>
    <item>
      <title>Windows Event Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Forwarding/m-p/548830#M91222</link>
      <description>&lt;P&gt;I have Windows Event Forwarding Configured and have installed a Universal Forwarder to send events to a Heavy Forward which then sends them on to the Indexers. I only have a basic configuration on the UF but I need to override a couple of fields such as computer name and index etc. I have setup the input.conf, props.conf and transforms.conf as detailed here&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/how-can-we-split-forwarded-windows-event-logs-by-host/m-p/61463" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/how-can-we-split-forwarded-windows-event-logs-by-host/m-p/61463&lt;/A&gt; on the HF but the configuration seems to get ignored.&lt;/P&gt;&lt;P&gt;I have also simplified this to just having the following in the input.conf on the HF but it makes no difference as events still go to the main index.&lt;/P&gt;&lt;PRE&gt;[WinEventLog://ForwardedEvents]
index=winevtlog
disabled = 0&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 16:26:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Forwarding/m-p/548830#M91222</guid>
      <dc:creator>Rhidian</dc:creator>
      <dc:date>2021-04-21T16:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Forwarding/m-p/548833#M91224</link>
      <description>&lt;P&gt;The inputs.conf changes should go on the UF because that is where the input takes place.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 16:49:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Forwarding/m-p/548833#M91224</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-04-21T16:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Forwarding/m-p/548852#M91227</link>
      <description>&lt;P&gt;Is there not a way to change the index from the HF?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 18:59:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Forwarding/m-p/548852#M91227</guid>
      <dc:creator>Rhidian</dc:creator>
      <dc:date>2021-04-21T18:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Forwarding/m-p/548860#M91229</link>
      <description>&lt;P&gt;Yes, there is, but it's much easier and less fragile to set the index on the UF.&amp;nbsp; IMO, the intermediate HF should be avoided when possible.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 20:24:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Forwarding/m-p/548860#M91229</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-04-21T20:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Forwarding/m-p/548865#M91230</link>
      <description>&lt;P&gt;Perfect thanks, any idea why the rest of the transform isn't working all my events are shown as coming from the WEC and not their actual devices also the source is ForwardedEvents and I would like that to be the actual log they came from, can this be done from the HF?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 21:10:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Forwarding/m-p/548865#M91230</guid>
      <dc:creator>Rhidian</dc:creator>
      <dc:date>2021-04-21T21:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Forwarding/m-p/548952#M91237</link>
      <description>&lt;P&gt;I can't help with the transform.&amp;nbsp; Try posting a new question with the transform in it.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 12:57:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Forwarding/m-p/548952#M91237</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-04-22T12:57:04Z</dc:date>
    </item>
  </channel>
</rss>

