Hi Splunkers,
I'm having issues ingesting Windows DNS Server Analytical logs. What's strange is that I am able to pull Audit logs with the following details in the inputs.conf file:
[WinEventLog://Microsoft-Windows-DNSServer/Audit]
disabled=0
index=dns
When I do the same thing for Analytical it does not work:
[WinEventLog://Microsoft-Windows-DNSServer/Analytical]
disabled=0
index=dns
Has anyone had any luck here?
Thank you!