Has anyone ever used this app?
Seems to be really poorly documented although I get the fact that it is a search time transformation.
Can someone break it down for me on how to use this thing?
Also curious as to whether you can take these search time transforms and apply them at index time.
Let me know when you have a moment.
Thanks.
Brian
the add-on is just fields extractions for WSUS services running on Windows Server 2008 R2.
Why do you want to extract fields at index time?
How should I proceed to install this?
If I place this in the etc apps folder of a a universal forwarder I've intalled on a remote system, can I expect this to pull the data for the System Management section KB numbers under the Splunk supported Windows app?
No. There is no inputs.conf