Removing Splunk forwarder from Windows hosts
This commit is contained in:
@@ -322,9 +322,9 @@ current_only = 0
|
||||
checkpointInterval = 5
|
||||
|
||||
[WinEventLog://WEC6-Sysmon]
|
||||
sourcetype = WinEventLog:Sysmon
|
||||
sourcetype = "XmlWinEventLog:Microsoft-Windows-Sysmon/Operational"
|
||||
source = WinEventLog:Sysmon
|
||||
index=wineventlog
|
||||
index=sysmon
|
||||
disabled = 0
|
||||
start_from = oldest
|
||||
current_only = 0
|
||||
|
||||
Reference in New Issue
Block a user