Hi Team,
I'm onboarding custom winevents to Splunk
[WinEventLog://Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational disabled = 0
index = wineventlog
above is the stanza I'm using it but I'm not able to see logs in Splunk.
Hi
Have you already working connection from UF to splunk indexers (You are getting other logs from that node)?
r. Ismo
hi @isoutamo Yes it is connected to indexer as I'm able to see application, security, and system logs from this machine