Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Sourcetype not changing for windows application logs

$
0
0

I have a universal forwarder sending the application logs for a windows 2003 server we have that only runs one application.

Here is what my inputs.conf stanza looks like:

[WinEventLog:Application]
index=radical_index
sourcetype=bizznezz

However the logs show up in splunk as WinEventLog:Application no matter how many times i restart the service.

Interestingly as a test i changed the hostname on the inputs.conf and that change was immediately reflected


Viewing all articles
Browse latest Browse all 13053

Trending Articles