Splunk Search

How to configure the input for ADFS

MikeBertelsen
Communicator

Based on what I've found I configured the following inputs.conf in a test tier as follows:
[WinEventLog://AD FS/Admin]
disabled = 0
sourcetype=adfs:winevt:admin.evtx
index=adfs

Nothing is being ingested. What am I missing???

Tags (2)
0 Karma

MikeBertelsen
Communicator

I ran the cli and all that displayed was:
Monitored Inputs

p_gurav
Champion

The logs are there in files, right?

0 Karma

MikeBertelsen
Communicator

yes the data is in the logs

0 Karma

MikeBertelsen
Communicator

We had a group review the issue and the problem was the inputs.conf was now under a "local\" directory.

0 Karma

p_gurav
Champion

Can you check below command:
./splunk list eventlog

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...