Getting Data In
Highlighted

Why is my Remote File & Directory input not automatically inputting data?

Engager

I currently have a Remote File & Directory Data Input on the following log
'C:\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx'

If I disable and enable the Data Input, it will import the log data. If I then go and make events within the log, it does not automatically import in to Splunk. However, if i go back and disable and enable the Data Input, it will import the backlog of events perfectly. Is there any way to automate this?

0 Karma
Highlighted

Re: Why is my Remote File & Directory input not automatically inputting data?

SplunkTrust
SplunkTrust

What are the inputs.conf settings for that file?

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: Why is my Remote File & Directory input not automatically inputting data?

Engager

the inputs.conf is below:

[monitor://C:\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx]
disabled = 0
index = remotelog
0 Karma