Getting Data In

editing input.conf is not reflects to system

manyaeons
New Member

hi, i just try to whitelist security log as below but it is not working
in fact non of these attribute reflects to system
i tried change to disabled=1 but logs keeps coming (even after restarted)

ver: 6.1

[WinEventLog://Security]
disabled = 0
current_only = 0
evt_resolve_ad_obj = 1
checkpointInterval = 5
whitelist = 4663
Tags (2)
0 Karma

gyslainlatsa
Motivator

hi manyaeons ,
try to follow these instructions

input.conf copy the file to the default folderand go stick it in thelocal folder and then make the change to put in local disabled=1
splunk then restarts. during startup, splunk will first consult the local file before the default folder and take into account the change.
I hope it will work

please forgive my english.

0 Karma

manyaeons
New Member

note:using wmi not forwarder
and yes it is inputs.conf

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...