Getting Data In

editing input.conf is not reflects to system

manyaeons
New Member

hi, i just try to whitelist security log as below but it is not working
in fact non of these attribute reflects to system
i tried change to disabled=1 but logs keeps coming (even after restarted)

ver: 6.1

[WinEventLog://Security]
disabled = 0
current_only = 0
evt_resolve_ad_obj = 1
checkpointInterval = 5
whitelist = 4663
Tags (2)
0 Karma

gyslainlatsa
Motivator

hi manyaeons ,
try to follow these instructions

input.conf copy the file to the default folderand go stick it in thelocal folder and then make the change to put in local disabled=1
splunk then restarts. during startup, splunk will first consult the local file before the default folder and take into account the change.
I hope it will work

please forgive my english.

0 Karma

manyaeons
New Member

note:using wmi not forwarder
and yes it is inputs.conf

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...