TA_ETW icon indicating copy to clipboard operation
TA_ETW copied to clipboard

custom index and sourcetype doesn't work

Open rafadvega opened this issue 4 years ago • 0 comments

hello,

When I change the index in the config yaml or in the inputs.conf, I stop receiving events in splunk. The index is correctly created in splunk. I only get events when I don't set index or sourcetype, and the events are stored in index = main source = TA_ETW: // ETW_events and sourcetype = TA_ETW. In the splunk logs I don't find any error events.

Is there an option to enable any logging on the app?

thanks!

rafadvega avatar Feb 01 '21 08:02 rafadvega