Getting Data In

How to edit my universal forwarder monitor stanza to index Active Directory server logs?

anaqvi
Explorer

I am trying to monitor the Active Directory Server for logs. I have a universal forwarder installed on a Windows AD Server, and there are logs at the following path:

%SystemRoot%\System32\Winevt\Logs\

How can I monitor it? I have tried the following, but it does not work:

[monitor://%SystemRoot%/System32\Winevt\Logs]
targetDC = hqdc06
baseline = false
disabled = 0
index = wineventlog
renderXml=false
Sourcetype = Active Directory
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi anaqvi,
probably the problem is the slash (/) after %SystemRoot%.
Every way, aren't you able to define %SystemRoot%?

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...