I have set up the input files in Splunk to pull the basic windows event logs, application, security, setup, and system. However, I have a program that shows up beneath those for in event vewer under application and services logs. I used the file path and the [\Wineventlog: Port Protection Program] but neither imported the data. Is there a way to make the log behave the same as the other four logs? I didn't have this problem with Roxio, but events for that popped up in the Application log already.