Hi,
Anybody knows how to include the windows server backup logs using Splunk_TA_windows addon? I have tried adding the following configuration to local\inputs.conf but it does not seem to work.
[WinEventLog:Microsoft-Windows-Backup/Operational]
disabled = 0
index = wineventlog
renderXml=false
start_from = oldest
checkpointInterval = 5
Any suggestions please?
Hi,
Can you please try below stanza ?
[WinEventLog://Microsoft-Windows-Backup]
disabled = 0
index = wineventlog
renderXml=false
start_from = oldest
checkpointInterval = 5
Update: stanza updated.
Hi,
Can you please try below stanza ?
[WinEventLog://Microsoft-Windows-Backup]
disabled = 0
index = wineventlog
renderXml=false
start_from = oldest
checkpointInterval = 5
Update: stanza updated.