From several posts I have read that best practice for windows events are to forward them to a winevents index. I've just set up Splunk and at first I sent the data to default main, but recently changed it to winevents.
When I open the Windows Infrastructure app the reports only show indexed data from main and not from winevents index. I've tried changing all index references to index=winevents, but still no success.
Can anyone point me towards which config files I need to change to see the correct data in the reports?
And am I right that it should be indexed to Winevents?
... View more