I am now monitoring the Windows event log directory, the corresponding entry on my inputs.conf file says:
[monitor://C:WindowsSystem32WinevtLogsApplication.evtx]
disabled = false
I can view the entries through the Event Viewer. However these aren't being forwarded by the forwarder, the splunkd log file entry shows:
06-05-2012 13:21:05.665 -0400 INFO WinEventLogInputProcessor - main-thread: Finished processing existing Windows Event Log 'C:WindowsSystem32WinevtLogsApplication.evtx': total_events='0' with empty_msg='0'.
Any suggestions/work arounds would be appreciated.
... View more