All,
Just working with Splunk_TA_Windows today and noticed that there is no specified sourcetype in inputs.conf and I don't see how the sourcetype is found in props.conf. Any idea how this is getting it's sourcetype? Would I be hurting anything to add it on?
[WinRegMon://default]
disabled = 1
hive = .*
proc = .*
type = rename|set|delete|create
[WinRegMon://hkcu_run]
disabled = 1
hive = \\REGISTRY\\USER\\.*\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\.*
proc = .*
type = set|create|delete|rename
[WinRegMon://hklm_run]
disabled = 1
hive = \\REGISTRY\\MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\.*
proc = .*
type = set|create|delete|rename