Dears,
How to set inputs file for collect WinEventLog for File Replication Service?
I try to add two kind of stanza in splunkforwarder file "$SPLUNK_HOME/etc/system/local/inputs.conf" as below:
But It doesn't work. Please help.
[WinEventLog:File Replication Service]
disabled=0
sourcetype="WinEventLog:File Replication Service"
index=windows
or
[WinEventLog://File Replication Service]
disabled = 0
Hi otis_huang,
You can refer this doc below:
https://docs.splunk.com/Documentation/ActiveDirectory/1.2.2/DeployAD/Configureanddeploythetechnicala...
Let me know if this helps!!
Hi otis_huang,
You can refer this doc below:
https://docs.splunk.com/Documentation/ActiveDirectory/1.2.2/DeployAD/Configureanddeploythetechnicala...
Let me know if this helps!!
It's AD server (Windows 2012 Enterprise).
Which windows version you are using?