Hi all Getting this message : ERROR ExecProcessor [3700 ExecProcessor] - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - WinEventMon::configure: Failed to find Event Log with channel name='Microsoft-AzureMfa-AuthZ/AuthZAdminCh' I've tried numerous combinations in the stanza such as : WinEventLog://Microsoft-AzureMfa-AuthZ/AuthZAdminCh WinEventLog://Microsoft-AzureMfa-AuthZ-AuthZAdminCh WinEventLog://Microsoft/AzureMfa/AuthZ/AuthZAdminCh The Windows Event Log chain for the AuthZAdminCh source is in the attachment. Just not quite sure where I'm going wrong. Appreciate some advice.
... View more