@gcusello Perfectly valid questions 🙂 SEDCMD is for the correct sourcetype? - I think this may be relevant. There was an upgrade on some of the TA's recently. The previous winevent sourcetypes are now the "source". So I think I may need to change the stanza to [source::my_winevent_source] in props.conf did you tried to put both on HF and Ind? - No, this is just on the HF where it also indexes the data did you restarted HF? - Yes
... View more