Getting Data In

Splunk_TA_Windows Winregistry Sourcetype missing?

daniel333
Builder

All,

Just working with Splunk_TA_Windows today and noticed that there is no specified sourcetype in inputs.conf and I don't see how the sourcetype is found in props.conf. Any idea how this is getting it's sourcetype? Would I be hurting anything to add it on?

[WinRegMon://default]
disabled = 1
hive = .*
proc = .*
type = rename|set|delete|create

[WinRegMon://hkcu_run]
disabled = 1
hive = \\REGISTRY\\USER\\.*\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\.*
proc = .*
type = set|create|delete|rename

[WinRegMon://hklm_run]
disabled = 1
hive = \\REGISTRY\\MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\.*
proc = .*
type = set|create|delete|rename
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...