...meta field in the windows stanza and the entity_type::windows_host is all there.
- perfmon::CPU is all there.
So its weird why i am getting N/A for cpu utilization on the windows entity overview...
Hello all,
I am using splunk Enterprise 7.3.1, with the windows apps and the AD add-on for windows AD.
I get no data in the WindowsOverview or the AD overview. There is no current data in the w...
...eployment server. This works fine, the client checks in, my apps get pushed to it, all fine. For windows logs, I'm using the Splunk TA for Windows (https://splunkbase.splunk.com/app/742/#/overview) w...
Hi, my name is hamanako. I would like to use "Windows Event Code Security Analysis", but when I select the "Lookup OverView" or "Table Analysis" menu, I get the following error. Please let me k...
...plunk documentation?
Suggestion: Please, don't forget about the Windows platform as you write your documentation.
There are still two or three of us Windows users still around.
Happy holidays.
Thanks
...etails App TA-winfw already installed However its missing any IP realetd info like src ip , dst ip and protocol. However I can see these fileds in local file stored at "C:\Windows\System32\L...
...e try to search for a specific or wildcard event (ie: print logs) we only receive results from the Linux servers but not the Windows servers. I was suggested to check the .conf files for Windows TA, b...
...dded dropdowns to my dashboard to filter this data by a user-selected time window for every day in the one month range. The four dropdowns correspond to the start hour, start minute, end hour, a...
Hi, I'm testing the Security Essentials app with just onboarding Linux logs. Nevertheless the Content Overview shows "available content" for multiple sources, e.g. Windows. Within the dashboard S...
Hi,
I'm sending logs from Windows machines to a log group in CloudWatch that sends to Splunk via Lambda function.
These logs are arriving in Splunk in the wineventlog sourcetype, but the parse i...