Hi All, It would be great help if anyone help me figure out this.
App is deployed in the UFs to receive such logs in splunk under the index wineventlog.
I can see 2 different sourcetypes (xmlwineventlog, XmlWinEventLog) under the wineventlog index
sourcetype : XmlWinEventLog (source : "XmlWinEventLog:Application", "XmlWinEventLog:Security", "XmlWinEventLog:System")
sourcetype : xmlwineventlog (source : "WinEventLog:Microsoft-Windows-Sysmon/Operational", "WinEventLog:Microsoft-Windows-Windows Defender/Operational")
Please help me where should I need to check these exact difference of two distinct case sensitive sourcetypes. Thanks
It is not clear to me what exactly you want to check. Please can you clarify?
Hi, I wanted to know the exact path where I can see the mentioned sourcetypes. So that I can check under which category 2 different sourcetypes are defined and if possible, I can make it as a single sourcetype since both are of same name
Try looking in inputs.conf