Splunk Dev

How to set inputs file for collect WinEventLog for File Replication Service

otis_huang
New Member

Dears,

How to set inputs file for collect WinEventLog for File Replication Service?
I try to add two kind of stanza in splunkforwarder file "$SPLUNK_HOME/etc/system/local/inputs.conf" as below:
But It doesn't work. Please help.

stanza:

[WinEventLog:File Replication Service]
disabled=0
sourcetype="WinEventLog:File Replication Service"
index=windows

or

[WinEventLog://File Replication Service]
disabled = 0

Tags (1)
0 Karma
1 Solution

deepashri_123
Motivator
0 Karma

deepashri_123
Motivator

Hi otis_huang,

You can refer this doc below:
https://docs.splunk.com/Documentation/ActiveDirectory/1.2.2/DeployAD/Configureanddeploythetechnicala...

Let me know if this helps!!

0 Karma

otis_huang
New Member

It's AD server (Windows 2012 Enterprise).

0 Karma

p_gurav
Champion

Which windows version you are using?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...