Hi All,
I have a question on how this should be approached. Stage:
Each server type has its own server class, and server classes use the same Windows TA but with a different wmi.conf. Everything is working well. Now, I hit a server type A with application A AND application B together on it, thus, I simply added to both server classes.
Outcome: I get application A logs but not application B. How to go around it? I don't want to create a special server class C where this happens, as this is only a portion of scope and management of such server classes would become horrible.
Windows TA is a copy of each other, just wmi.conf is changed.
Thank you for your help!
After triple checking everything, noticed that I have not changed the stanza name... of course with the same stanza name it will not work 🙂 Though interesting how Splunk decides the precedence of one stanza over the other.
After triple checking everything, noticed that I have not changed the stanza name... of course with the same stanza name it will not work 🙂 Though interesting how Splunk decides the precedence of one stanza over the other.
Glad you solved it already 🙂
One suggestion: don't copy the entire windows TA. Just deploy the default TA everywhere and create small separate add-ons that contain the local wmi.conf.