I installed the Universal Forwarder using the MSI, specified server info, but didn't check any boxes for wineventlog and such. I can see the PC checking in on the Splunk server, but it's not receiving any data. This is my ...\etc\system\local\inputs.conf
[default]
host = PBDC-LT-16
[WinEventLog:System]
interval=60
index=wineventlog
disabled=0
[WinEventLog:Security]
interval=60
index=wineventlog
disabled=0
[WinEventLog:Application]
interval=60
index=wineventlog
disabled=0
↧