Based on what I've found I configured the following inputs.conf in a test tier as follows:
[WinEventLog://AD FS/Admin]
disabled = 0
sourcetype=adfs:winevt:admin.evtx
index=adfs
Nothing is being ingested. What am I missing???
I ran the cli and all that displayed was:
Monitored Inputs
The logs are there in files, right?
yes the data is in the logs
We had a group review the issue and the problem was the inputs.conf was now under a "local\" directory.
Can you check below command:
./splunk list eventlog