They fixed the docs on inputs.conf. @rovechikin Should of submitted a change on the docs inputs.conf page to save people the frustration.
... View more
That fixes it.
%SystemRoot%\System32\Winevt\Logs\ForwardedEvents.evtx
The space [WinEventLog:Forwarded Events] does not work. Hopefully they fixed the documentation. ( I sent a documentation fix)
http://docs.splunk.com/Documentation/Splunk/5.0.1/admin/Inputsconf
I dont have enough credit to upvote the above answer.
... View more