- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Monitor events from Custom Views of Windows EventViewer
arber
Communicator
01-06-2017
03:49 AM
Hi,
we are trying to monitor some events on a Custom View created on the Windows Event Viewer like in the pic below
We tried to get those events adding the stanza [WinEventLog://MonitoredEvents] but nothing is shown in Splunk. Has anyone encountered this before ?
Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

nickhills
Ultra Champion
01-15-2018
08:48 AM
It seems you have built an event filter, sadly the Splunk UF can not leverage this directly, however if you are filtering these events by something as simple as an event id, its relatively simple to replicate this on your forwarders inputs.conf using white listing.
If my comment helps, please give it a thumbs up!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
iserje
New Member
01-15-2018
05:39 AM
This is not the log, it's a view.
