- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Dears,
How to set inputs file for collect WinEventLog for File Replication Service?
I try to add two kind of stanza in splunkforwarder file "$SPLUNK_HOME/etc/system/local/inputs.conf" as below:
But It doesn't work. Please help.
stanza:
[WinEventLog:File Replication Service]
disabled=0
sourcetype="WinEventLog:File Replication Service"
index=windows
or
[WinEventLog://File Replication Service]
disabled = 0
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi otis_huang,
You can refer this doc below:
https://docs.splunk.com/Documentation/ActiveDirectory/1.2.2/DeployAD/Configureanddeploythetechnicala...
Let me know if this helps!!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi otis_huang,
You can refer this doc below:
https://docs.splunk.com/Documentation/ActiveDirectory/1.2.2/DeployAD/Configureanddeploythetechnicala...
Let me know if this helps!!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

It's AD server (Windows 2012 Enterprise).
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Which windows version you are using?
