Does the windows app work with 2008 event log files? Is the Windows app the best way to monitor windows logs?
The Windows app is the best way to monitor Windows Event Logs, but it doesn't monitor the evtx files. (The files are [or can be] created by the Event Logging system, but the Splunk WinEventLog monitor talks directly to the Event Logging system rather than looking.)
So then what is the recommended method for ingesting evtx files from Windows 2008? Also, when I enable and configure the Windows App to monitor my event logs, on both 2003 and 2008 servers, nothing is getting ingested. I verified that my account has full control over the Splunk installation directory. I am now manually entering the Windows stanzas in the inputs.conf file....