Hello,
I want to deploy Splunk to many server with LightForwarder enabled, but forwarding only Windows Security Event Log. From unattended configuration standpoint I got everything covered using CLI commands, but I can't figure out how to disable default indexing of Applications and System logs from CLI. Any clues?
Thanks, Marcin