All Apps and Add-ons

Index non winevent log sources

newsplunker1
Path Finder

Hi, 

I'm trying to index the following sources with the below configs. Im using Splunk UF. Im receiving other logs such as internal , win event security/application so no firewall or communication issues between the client and server 

[WinEventlog://Microsoft-AzureADPasswordProtection-DCAgent/Admin]
index=main
disabled=0

[WinEventlog://Microsoft-AzureADPasswordProtection-DCAgent/Operational]
index = main
disabled = 0

 

Thanks 

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @newsplunker1 ,

probably it could be a good idea to configure different destination indexes for different kind of logs:

I usually use "wineventlog" for Windows Event logging, "windows" for the other windows data source and "perfmon" for performance monitoring logs.

Even if the main rules to assign an index are Access grants and retention.

And anyway, never use main!

Ciao.

Giuseppe

0 Karma

newsplunker1
Path Finder

@gcusello This was just for quick testing in the dev env but in the prod, i do have specific indexes for each category. 

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...