Getting Data In

Where does the mapping of Account Name to src happen for the WinEventLog data?

danielbb
Motivator

I'm not clear where and when the src field gets its value for the WinEventLog data.

Tags (3)
0 Karma

woodcock
Esteemed Legend

This should be happening in the Splunk_TA_windows app. Check the props.conf and transforms.conf in the default directory.

gcusello
SplunkTrust
SplunkTrust

HI danielbb,
This question doesn't seem a Splunk question, could you give more details?

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...