I would create a new index name call winprinmon and the specify it in in the input file. Also make sure you enable have enable Microsoft-Windows-PrintService/Operational in Windows Event Viewer and configure GP under computer configuration> admin templates> Printers> Allow job name in event logs to enable. To see files name being printing. [WinEventLog://Microsoft-Windows-PrintService/Operational] disabled = 0 renderXml = 1 checkpointInterval = 5 evt_resolve_ad_obj = 1 start_from = newest # only index events with these event IDs. whitelist = 307,805 index=winprinmon
... View more