Getting Data In

Custom WinEvent in Splunk- Can't see logs in Splunk?

vikramauto
New Member

Hi Team,

I'm onboarding custom winevents to Splunk

[WinEventLog://Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
disabled = 0
index = wineventlog

above is the stanza I'm using it but I'm not able to see logs in Splunk.

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Have you already working connection from UF to splunk indexers (You are getting other logs from that node)?

r. Ismo

0 Karma

vikramauto
New Member

hi @isoutamo Yes it is connected to indexer as I'm able to see application, security, and system logs from this machine

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...