I am getting this message when I do windows infra guided set-up,
WARNING: Search "sourcetype="WinRegistry*" | head 5" did not return any events in the last 24 hours
I have already checked Splunk_TA_Windows - inputs.conf in local and default folder, there is no such sourcetype="WinRegistry*. It does exist in props.conf and transforms.conf but no way to enable it.
you might also want to look for this input [WinRegMon://default]