All Apps and Add-ons

Index non winevent log sources

newsplunker1
Path Finder

Hi, 

I'm trying to index the following sources with the below configs. Im using Splunk UF. Im receiving other logs such as internal , win event security/application so no firewall or communication issues between the client and server 

[WinEventlog://Microsoft-AzureADPasswordProtection-DCAgent/Admin]
index=main
disabled=0

[WinEventlog://Microsoft-AzureADPasswordProtection-DCAgent/Operational]
index = main
disabled = 0

 

Thanks 

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @newsplunker1 ,

probably it could be a good idea to configure different destination indexes for different kind of logs:

I usually use "wineventlog" for Windows Event logging, "windows" for the other windows data source and "perfmon" for performance monitoring logs.

Even if the main rules to assign an index are Access grants and retention.

And anyway, never use main!

Ciao.

Giuseppe

0 Karma

newsplunker1
Path Finder

@gcusello This was just for quick testing in the dev env but in the prod, i do have specific indexes for each category. 

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...