|
Hello, I am having a rather strange problem dealing with source's that have been changed. I have a WinEventLog:Application input, then on my forwarder I am re-writing the source field to be something more contextual. The new source is coming across fine, I can see it in the dashboard_live source summary page, but searching for source="MSW_GW_EVL_NAP" returns no results. However, searching for something like sourcetype="WinEventLog:Application" source!="WinEventLog:Application", the events are there and the correct source is showing. I am using props / transforms on my forwarder, and have done this in a similar way for other source's, and it has worked fine. Please help! props.conf
transforms.conf
|
