We are using WinHostMon://service stanza in input.conf to monitor the service status on windows hosts. But it doesn't seems to be retrieving the status of some services.. Eg: Splunk , Snare... Below is the config used. Any limitation for WinHostMon://Service ?.
[WinHostMon://Service]
index = winsvc
interval = 300
type = service
↧