Quantcast
Viewing all articles
Browse latest Browse all 1551

WMI Input field data truncation

So I would like to implement a WMI based input via WMI.conf among a subset of Splunk Universal Forwarders. In this case I'd like to log PnpSignedDrivers. Here is the input I have defined in WMI.conf [WMI:Win32_PnPSignedDriver] interval = 10 wql = SELECT Description, DeviceClass, DeviceID, DeviceName, DriverDate, DriverVersion, FriendlyName, InfName, IsSigned, Location, Manufacturer FROM Win32_PnPSignedDriver I'm getting events BUT WMI object properties such as DeviceName seem to get truncated after the first word. For instance, in Splunk the corresponding event for the DeviceName of my network interface is "Broadcom", but the actual propery value of the WMI object is "Broadcom 802.11n Network Adapter". Am I doing something wrong is this a bug?

Viewing all articles
Browse latest Browse all 1551

Trending Articles