Hi Splunk Community,
Can one configure inputs.conf to forward events based on a "Custom Views" in Event Viewer?
Specifically, we are looking to forward the events Certification Authority events.
Take a look at my answer here (the nested one) in case that helps:
disabled = 0
start_from = oldest
index = yourindexname