Splunk Enterprise Security

src filed must be defined

New Member


i saw that you had this issue years ago: I've installed Splunk Security Essentials App and Splunk TA for Windows. However, when I run the Data Source Check I get a notice that the src field must be defined in the Security logs. It says the TA for Windows should provide the field definition. I think this needs to be included in the inputs.conf file for the TA for Windows app. Any ideas how to resolve the message and/or what to add to the inputs.conf file?


i was wondering if you found any solution for that. @sbgoldberg13 

Labels (2)
0 Karma