Getting Data In

Microsoft web application proxy log format inputs.conf

tarricop
Loves-to-Learn

I'm trying to configure my forwarder on a Windows server to send the Web Application Proxy logs.  I'm using this format but it doesn't seem to be sending.  I also added ADFS and that worked.  Syntax is as follows:

[WinEventLog://AD FS/Admin]

disabled = 0

[WinEventLog://Web Application Proxy/Admin]

Disabled = 0

I couldn't find a documented list for all of the different windows logs.  Any help would be appreciated. 

Labels (3)
0 Karma

jvsplunker
Loves-to-Learn Everything

Did you ever figure out the [WinEventLog://Web Application Proxy/Admin] ? Wanting to splunk these logs  as well.

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...