Getting Data In

I am trying to bring in windows logs from a clients server, but nothing is showing. I created a new application.

nls7010
Path Finder

This is the inputs from the app I created for the windows logs:

[WinEventLog://Application]
index = replicate3
disabled = 0
start_from = oldest
current_only = 0
checkpointInterval = 5
renderXml=0

[WinEventLog://Security]
index = replicate3
disabled = 0
start_from = oldest
current_only = 0
evt_resolve_ad_obj = 1
checkpointInterval = 5
blacklist1 = EventCode="4662" Message="Object Type:(?!\s*groupPolicyContainer)"
blacklist2 = EventCode="566" Message="Object Type:(?!\s*groupPolicyContainer)"
renderXml=0

[WinEventLog://System]
index = replicate3
disabled = 0
start_from = oldest
current_only = 0
checkpointInterval = 5
renderXml=0

 

I created a special index for it, but it is not getting any results.  I also have sent over the splunk TA for windows logs, but still nothing is coming in.  The index was created successfully and the apps show on the client.  What else am I missing.

Labels (4)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...