Quantcast
Viewing all articles
Browse latest Browse all 47296

After editing inputs.config on forwarder data shows up unreadable

Hi i edited the inputs.cinfig file on my forwarder and once i restart splunk etc i see the data on search but it is not readeble. can anyone tell me what i am doing wrong? [default] host = xxxxxxx [monitor://C:\Windows\System32\winevt\Logs\*] disabled = false index=xxxxxx followTail = 0 sourcetype = sync i have all the other data coming in fine. Thanks, ![alt text][1] [1]: /storage/temp/216658-sync-log3.png

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>