when we try this command, index="test_1" | collect index="sample_index" it is working, but when trying the command | makeresults or | inputlookup command, it is not collecting to the index
... View more
When I run | makeresults command then collect it to summary index there is no result. I am testing this to Search Head in Cluster environment.
sample code:
| makeresults | eval a = "1" | collect index = "sample_index"
... View more
Hi, I appreciate your help, but it still not working on my end 😞 I have tried the code but no result in pulling data. This is the inputs.conf [WinEventLog://Microsoft-Windows-TaskScheduler/Operational] disabled = 0 start_from = oldest current_only = 1 checkpointInterval = 5 renderXml = true whitelist1 = Message=:'TaskName'\>\\Service Process\\<: index = winevents_index
... View more
How will I whitelist specific TaskName in inputs.conf in Splunk forwarder configuration from WinEventLog Task Scheduler/Operational .
Pulled data Example:
....<Data Name='TaskName'>\Job 1</Data>.....
....<Data Name='TaskName'>\Job 2</Data>.....
....<Data Name='TaskName'>\Other 1</Data>.....
I only need to pull data of Job 1 and Job 2. How can I filter multiple jobs in inputs.conf
... View more