Splunk Search

How to configure the input for ADFS

MikeBertelsen
Communicator

Based on what I've found I configured the following inputs.conf in a test tier as follows:
[WinEventLog://AD FS/Admin]
disabled = 0
sourcetype=adfs:winevt:admin.evtx
index=adfs

Nothing is being ingested. What am I missing???

Tags (2)
0 Karma

MikeBertelsen
Communicator

I ran the cli and all that displayed was:
Monitored Inputs

p_gurav
Champion

The logs are there in files, right?

0 Karma

MikeBertelsen
Communicator

yes the data is in the logs

0 Karma

MikeBertelsen
Communicator

We had a group review the issue and the problem was the inputs.conf was now under a "local\" directory.

0 Karma

p_gurav
Champion

Can you check below command:
./splunk list eventlog

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...