Archive

How to configure the input for ADFS

Communicator

Based on what I've found I configured the following inputs.conf in a test tier as follows:
[WinEventLog://AD FS/Admin]
disabled = 0
sourcetype=adfs:winevt:admin.evtx
index=adfs

Nothing is being ingested. What am I missing???

Tags (2)
0 Karma

Communicator

I ran the cli and all that displayed was:
Monitored Inputs

Champion

The logs are there in files, right?

0 Karma

Communicator

yes the data is in the logs

0 Karma

Communicator

We had a group review the issue and the problem was the inputs.conf was now under a "local\" directory.

0 Karma

Champion

Can you check below command:
./splunk list eventlog

0 Karma