Getting Data In

editing input.conf is not reflects to system

manyaeons
New Member

hi, i just try to whitelist security log as below but it is not working
in fact non of these attribute reflects to system
i tried change to disabled=1 but logs keeps coming (even after restarted)

ver: 6.1

[WinEventLog://Security]
disabled = 0
current_only = 0
evt_resolve_ad_obj = 1
checkpointInterval = 5
whitelist = 4663
Tags (2)
0 Karma

gyslainlatsa
Motivator

hi manyaeons ,
try to follow these instructions

input.conf copy the file to the default folderand go stick it in thelocal folder and then make the change to put in local disabled=1
splunk then restarts. during startup, splunk will first consult the local file before the default folder and take into account the change.
I hope it will work

please forgive my english.

0 Karma

manyaeons
New Member

note:using wmi not forwarder
and yes it is inputs.conf

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...