In the Server 2008 Event Viewer there are now a "Microsoft --> Windows" folders nested under the "Applications and Services Logs" section. What should the Splunk inputs.conf look like for the event logs under the "Microsoft" --> "Windows" folder. Specifically I am looking for the "PrintService --> Operational", but if anybody has any of these other logs being indexed the base input should be the same
I tried the following with no success...
[WinEventLog:Microsoft:Windows:PrintService Operational] [WinEventLog:PrintService Operational]
Thanks in advance...
This is stanza required
Thanks to Ellen Hom with Splunk Support
So is that all you need to have in your input.conf file ? or do you need somthing somewhere else ? I need to monitor that particular event log however im getting nothing currently, I did merge that event log with the system event log which did sort or work but not as I need it to.
dont worry managed to get it working with this -
disabled = 0
startfrom = oldest
currentonly = 0
after some restarting if the forwarders 🙂
The add data interface will list these out as well. Even if you intended to deploy to a forwarder, you can still create the stanza as a sample on one Splunk to make sure the syntax is correct.