Quantcast
Channel: Questions in topic: "universal-forwarder"
Viewing all articles
Browse latest Browse all 1551

Splunk App for Windows Infrastructure: Why do events appear to be broken sent from Microsoft Windows Event Collectors via universal forwarders?

$
0
0
Hello; I am running several Microsoft Windows Event Collectors, and data contained within the App for Windows Infrastructure; mostly events, appear to be broken. If I search my data for "ComputerName" instead of "host", my searches seem to work; haven't tried in a dashboard or report. Do I have to change the sourcetype on my event collectors inputs.conf, modify its transforms, re-write the dashboard searches? I am looking for the easiest and most efficient route here, one that will not break later with an upgrade. Thank you!

Viewing all articles
Browse latest Browse all 1551

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>