Splunk Search

wql query not returning any events [WMI:Services]



Below query in wmi.conf file is not returning any events . But other queries are working.

Please do suggest if anything is wrong

interval = 60
wql = SELECT Name, State, Status FROM Win32_Service WHERE (Name = '*DynamicsNav*' OR Name = '*SQL*' OR Name = '*MsDts*')
disabled = 0

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Security Highlights: September 2022 Newsletter

 September 2022 The Splunk App for Fraud Analytics (SFA) is now Splunk SupportedUse your existing Splunk ...

Platform Highlights | September 2022 Newsletter

 September 2022 What’s New in 9.0 and How to UpgradeGet a walk through of what is new Splunk Enterprise 9.0 ...

Observability Highlights | September 2022 Newsletter

 September 2022 Splunk Observability SuiteAccess to "Classic" SignalFx Interface Will be Removed on Sept 30, ...