Hi! I'm trying to collect the local splunk server Windows Application event logs. I would like them in non_XML format. In .../app/Splunk_TA_windows/inputs.conf stanza I added:
[WinEventLog://Application]
index = splunk_server_app
source = WinEventLog:Application
sourcetype = WinEventLog
disabled = 0
renderXML = 0
I'm getting events but they are in XML format. Using Splunk Enterprise version 8.1.4.
Any help wond be appreciated. Thanks