<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do we setup &amp;quot;WinEventLog://HardwareEvents&amp;quot; and &amp;quot;WinEventLog://Setup&amp;quot; in splunk_nix_windows inputs.conf in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-we-setup-quot-WinEventLog-HardwareEvents-quot-and-quot/m-p/355096#M6563</link>
    <description>&lt;P&gt;I tried to deploy the splunk_TA_Windows app from deployment server to the Host with splunk forwarder after the changes in inputs.conf, where I am able to see events indexed from "[WinEventLog://Security]", "[WinEventLog://Application]"and "[WinEventLog://System]" but not from "setup" and "HardwareEvents".&lt;/P&gt;

&lt;P&gt;Do we need to make any other changes in Splunk_TA_windows app on Deployment server in order to get the missing logs to be indexed on splunk.&lt;/P&gt;

&lt;P&gt;I did not find any script related to"HardwareEvents" or "Setup" at Splunk_TA_windows/samples where as we have for application,security and system&lt;/P&gt;

&lt;P&gt;Can anyone help me with this??.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 14:30:49 GMT</pubDate>
    <dc:creator>rangineniarunku</dc:creator>
    <dc:date>2020-09-29T14:30:49Z</dc:date>
    <item>
      <title>How do we setup "WinEventLog://HardwareEvents" and "WinEventLog://Setup" in splunk_nix_windows inputs.conf</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-we-setup-quot-WinEventLog-HardwareEvents-quot-and-quot/m-p/355094#M6561</link>
      <description>&lt;P&gt;Can someone provide me the complete monitoring's stanzas for the "WinEventLog://HardwareEvents" and "WinEventLog://Setup" in inputs.conf for Splunk_TA_windows add-on. &lt;/P&gt;

&lt;P&gt;I doubt whether it is same as that we do it for Applications,Security and System?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:30:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-we-setup-quot-WinEventLog-HardwareEvents-quot-and-quot/m-p/355094#M6561</guid>
      <dc:creator>rangineniarunku</dc:creator>
      <dc:date>2020-09-29T14:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: How do we setup "WinEventLog://HardwareEvents" and "WinEventLog://Setup" in splunk_nix_windows inputs.conf</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-we-setup-quot-WinEventLog-HardwareEvents-quot-and-quot/m-p/355095#M6562</link>
      <description>&lt;P&gt;there it is&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog://Setup]
checkpointInterval = 5
current_only = 0
disabled = 0
index = wineventlog
start_from = oldest

[WinEventLog://HardwareEvents]
checkpointInterval = 5
current_only = 0
disabled = 0
index = wineventlog
start_from = oldest
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;indeed like all others &lt;BR /&gt;
hope it helps&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 23:24:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-we-setup-quot-WinEventLog-HardwareEvents-quot-and-quot/m-p/355095#M6562</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-06-15T23:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: How do we setup "WinEventLog://HardwareEvents" and "WinEventLog://Setup" in splunk_nix_windows inputs.conf</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-we-setup-quot-WinEventLog-HardwareEvents-quot-and-quot/m-p/355096#M6563</link>
      <description>&lt;P&gt;I tried to deploy the splunk_TA_Windows app from deployment server to the Host with splunk forwarder after the changes in inputs.conf, where I am able to see events indexed from "[WinEventLog://Security]", "[WinEventLog://Application]"and "[WinEventLog://System]" but not from "setup" and "HardwareEvents".&lt;/P&gt;

&lt;P&gt;Do we need to make any other changes in Splunk_TA_windows app on Deployment server in order to get the missing logs to be indexed on splunk.&lt;/P&gt;

&lt;P&gt;I did not find any script related to"HardwareEvents" or "Setup" at Splunk_TA_windows/samples where as we have for application,security and system&lt;/P&gt;

&lt;P&gt;Can anyone help me with this??.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:30:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-we-setup-quot-WinEventLog-HardwareEvents-quot-and-quot/m-p/355096#M6563</guid>
      <dc:creator>rangineniarunku</dc:creator>
      <dc:date>2020-09-29T14:30:49Z</dc:date>
    </item>
  </channel>
</rss>

