Getting Data In

How do I monitor Desired State Config event logs?

ericlarsen
Path Finder

I'm trying to monitor the Desired State Configuration event logs on some Windows servers. I cannot seem to get the monitor stanza to work. Here's the current stanza:

[WinEventLog://Microsoft-Windows-Desired State Configuration/Operational]

I've also tried removing the spaces in 'Desired State Configuration' with no luck.

Anyone successfully monitor these events? Any help would be greatly appreciated.
Thanks.

0 Karma
1 Solution

ericlarsen
Path Finder

For those curious, I got it working with this config:

[WinEventLog://Microsoft-Windows-DSC/Operational]

View solution in original post

0 Karma

ericlarsen
Path Finder

For those curious, I got it working with this config:

[WinEventLog://Microsoft-Windows-DSC/Operational]

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...