Splunk Enterprise Security

src filed must be defined

mahdis_jooon
New Member

hi

i saw that you had this issue years ago: I've installed Splunk Security Essentials App and Splunk TA for Windows. However, when I run the Data Source Check I get a notice that the src field must be defined in the Security logs. It says the TA for Windows should provide the field definition. I think this needs to be included in the inputs.conf file for the TA for Windows app. Any ideas how to resolve the message and/or what to add to the inputs.conf file?

 

i was wondering if you found any solution for that. @sbgoldberg13 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud? Learn how unique features like ...