Hi! I'm trying to collect the local splunk server Windows Application event logs. I would like them in non_XML format. In .../app/Splunk_TA_windows/inputs.conf stanza I added:
[WinEventLog://Application]index = splunk_server_appsource = WinEventLog:Applicationsourcetype = WinEventLogdisabled = 0renderXML = 0
I'm getting events but they are in XML format. Using Splunk Enterprise version 8.1.4.
Any help wond be appreciated. Thanks