I've followed the suggestions on this site but they didn't work.
Went to C:\Program Files\Splunk\etc\system\local and edited inputs.conf.
[WinEventLog://Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational]
disabled = 0
start_from = oldest
current_only = 0
Restarted Splunk (splunkd). Tried to add a computer, but still did not see this listed.
can you please add some specifics w/regards to where splunk is running and where the data that you're trying to index is?
I can, with the same issue
this is in a separate TA on a Windows Universal Forwarder. This log is not coming in.
[WinEventLog://Microsoft-Windows-TerminalServices-LocalSessionManager/Operational]
disabled = 0
index = eventlog_other
renderXml = false
start_from = oldest
From Btool:
C:\Program Files\SplunkUniversalForwarder\etc\apps\sft_win_eventlogs\local\inputs.conf [WinEventLog://Microsoft-Windows-TerminalServices-LocalSessionManager/Operational]
C:\Program Files\SplunkUniversalForwarder\etc\apps\sft_win_eventlogs\local\inputs.conf disabled = 0
C:\Program Files\SplunkUniversalForwarder\etc\apps\sft_win_eventlogs\local\inputs.conf renderXml = false
C:\Program Files\SplunkUniversalForwarder\etc\apps\sft_win_eventlogs\local\inputs.conf start_from = oldest
C:\Program Files\SplunkUniversalForwarder\etc\apps\sft_win_eventlogs\local\inputs.conf index = win_eventlog_other