Getting Data In

Custom Windows Event Log

Path Finder

Our developers have created a custom Windows Event Log to log events from an In-House develop app. What would be the best way to index this custom event log?

Tags (3)
0 Karma

Splunk Employee
Splunk Employee

Just add in an input stanza like this.

[WinEventLog:customname]
disabled = 0
index=windows