Hi All,
Can anyone advise me on below
I have Windows Application logs disabled already but I need one event ID that should be allowed.
you can give whitelist attribute in monitoring stanza for application events -
For ref - https://docs.splunk.com/Documentation/SplunkCloud/8.2.2106/Data/MonitorWindowseventlogdata