Getting Data In

Wildcard for Custom WinEventLogs

jodros
Builder

Our programmers code events to custom logs stored in the WinEventLog viewer. Instead of having to update the inputs.conf file for each new application and it's corresponding custom event log, is there a way to utilize wildcards? I know that they work for monitoring file directories, but I am unsure if that approach would work for WinEventLogs. We were thinking of prefacing each custom log with the same text and using wildcard in the inputs.conf. Currently this is not working for us. Example is below:

Log Names would begin with "ABC-"

[WinEventLog:ABC-*]
disabled = 0
start_from = oldest
current_only = 0
checkpointInterval = 5
sourcetype = dotnet
index = web

Any assistance would be appreciated.

Tags (2)
0 Karma

yannK
Splunk Employee
Splunk Employee

Wildcard in inputs.conf in a [WinEventLog:] stanza will not work.

I tested with
[WinEventLog:S*]
instead of
[WinEventLog:System]
[WinEventLog:Security] and failed.

jodros
Builder

Early morning bump. Anyone know if this can be accomplished? I am fine if I can use wildcards with the full path name. Any info would be appreciated.

0 Karma

jodros
Builder

So when I change it to the exact log name [WinEventLog:ABC-CustomApp] it works fine. Would really love to use the wildcard here in order to automatically pull in any new custom application logs.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...