Getting Data In

adding custom source override to wineventlog

Splunk Employee
Splunk Employee

Hello,

Is it possible to add a custom source override to a windows eventlog in the inputs.conf stanza?

0 Karma

Splunk Employee
Splunk Employee

Doesn't look like it according to inputs.conf, but you could always use an index-time transform.

0 Karma