I am using splunk lightweight to forward security events from domain controllers.
Is there a way to get the event ID's to be displayed? Or are those stripped out?
Previous Topic: splunk is taking too many gigs of space | Next Topic: Repeating Entries
I am using splunk lightweight to forward security events from domain controllers.
Is there a way to get the event ID's to be displayed? Or are those stripped out?
They are currently in the eventid field - check this field to display it. In future versions, we will include the event ID in the raw data.
Would you mind clarifying this? Where can i check this field?
Click on "Fields", which is below the timeline to the far left, check the box next to eventid, and click Apply.
You must be logged in to post a reply.
Flash required to play this video.
Click here to download the free Flash Player.