We all know that Windows reporting and event logging are a complete mess, so this might not be a Splunk issue but I have to ask.
I have set up inputs.config to ingest Windows print jobs on a UF -
[WinPrintMon://jobs]
type=job
index=winprintmon
I am getting multiple copies of some events and only part of some events and missing some entirely. I noticed that the interval defaults to 60 seconds. There is a "special value" of 0, that forces this scripted input to be run continuously, If I would set the interval to 0, would this help? Or maybe making the interval longer, say interval=300, would decrease the duplicates?
As always, any help would be greatly appreciated so I can stopping pestering my Server Admin 🙂
Scott
... View more