We are moving away from using Windows Event Collection to installing the Universal Forwarder on as many Windows machines as we can. I ran into an interesting issue that I don't know how to resolve.
Event 1646, when collected using WEC and then forwarded to Splunk shows this information, which doesn't appear if the same event is sent directly by the UF.
I copied the stanza used by the UF on the WEC server and deployed it to the machine where the event is generated but I am still not seeing the "extra" data when not using WEC. What am I missing? (Something easy, no doubt). Seems as though I don't see the "Message" field when the event is collected by the UF.
Thanks in advance.