The print server OS is Windows Server 2019 I would like to get PrintService-Admin log to Splunk. I tried the following in the input.conf of Universal Forwarder in print server. [WinEventLog://Microsoft-Windows-PrintService/Admin] disabled = 0 index = winps Which is found in https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77633 But I cannot find any events from the index. The log is enabled in the server, which is under Applications and Services Logs > Microsoft > Windows > PrintService I also tried to set the data input from web console to monitor the log file in folder: C:\Windows\System32\winevt\Logs With RegEx: Microsoft\-Windows\-PrintService.+\.evtx So i can get Microsoft-Windows-PrintService%4Admin.evtx AND Microsoft-Windows-PrintService%4Operational.evtx But also, no event is shown for the index. Hope somebody can help with this. Thanks
... View more