Logs from Microsoft Azure Active Directory Reporting Add-on for Splunk are in Chinese. Tried encoding it by setting the CHARSET value to AUTO as well as GB18030 in props.conf file. But still the same issue. Any thoughts what might resolve this issue?
[ms:aad:signin]
CHARSET=GB18030
[ms:aad:audit]
CHARSET=GB18030
... View more
Where do I find the logs of a universal forwarder that are installed in a domain controller?
We have universal forwarder installed in domain controller bu the logs for password change attempts are seen in the Domain controller but not in Splunk search head.
Please help to check if the universal forwarder has pushed the logs for password change attempt to the indexer/ heavy forwarder.
... View more