Hi All,
We have configures below stanza on SMB server(UF) and splunk forwarder to collect SMB logs,
[WinEventLog://Microsoft-Windows-SMBServer/Audit]
disabled = 0
start_from = oldest
current_only = 0
index = wineventlog
Can you please let us know if the above stanza worked for anyone to collect the logs or share any working stanza is appreciated.
TIA
Sharada