<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: windows ta addon not extracting action in Security</title>
    <link>https://community.splunk.com/t5/Security/windows-ta-addon-not-extracting-action/m-p/692637#M17967</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244593"&gt;@Chiranjeev&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what's the format of your logs?&lt;/P&gt;&lt;P&gt;it's the standard windows or a different one?&lt;/P&gt;&lt;P&gt;I experienced many issues using a concentrator for windows logs.&lt;/P&gt;&lt;P&gt;If the format is different, you shuld reparse them.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jul 2024 12:25:09 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-07-08T12:25:09Z</dc:date>
    <item>
      <title>windows ta addon not extracting action</title>
      <link>https://community.splunk.com/t5/Security/windows-ta-addon-not-extracting-action/m-p/692601#M17959</link>
      <description>&lt;P&gt;I am having issues with action extraction on my windows addon . for example the eventcode 4624 should have an action value of &lt;STRONG&gt;success&amp;nbsp;&lt;/STRONG&gt;,but nothing is being extracted and this eventcode constitutes majority of the data .the status is being extracted correctly&amp;nbsp; as success.does anyone know how action is being extracted for this eventcode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 08:13:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/windows-ta-addon-not-extracting-action/m-p/692601#M17959</guid>
      <dc:creator>Chiranjeev</dc:creator>
      <dc:date>2024-07-08T08:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: windows ta addon not extracting action</title>
      <link>https://community.splunk.com/t5/Security/windows-ta-addon-not-extracting-action/m-p/692615#M17961</link>
      <description>&lt;P&gt;There is something wrong.&lt;/P&gt;&lt;P&gt;But seriously - you haven't shown us anything regarding your data and your configuration. You haven't told us what your architecture is and where this addon is installed.&lt;/P&gt;&lt;P&gt;My glass orb is undergoing annual maintenance...&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 10:01:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/windows-ta-addon-not-extracting-action/m-p/692615#M17961</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-08T10:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: windows ta addon not extracting action</title>
      <link>https://community.splunk.com/t5/Security/windows-ta-addon-not-extracting-action/m-p/692621#M17962</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244593"&gt;@Chiranjeev&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;did you enabled inputs in the add-on? by default they are disabled.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 10:24:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/windows-ta-addon-not-extracting-action/m-p/692621#M17962</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-07-08T10:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: windows ta addon not extracting action</title>
      <link>https://community.splunk.com/t5/Security/windows-ta-addon-not-extracting-action/m-p/692627#M17963</link>
      <description>&lt;P&gt;we have a centralized collector via WEF for our windows logs where a uf with windows addon is sending logs to splunkcloud,where also we have a ta addon .&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 11:26:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/windows-ta-addon-not-extracting-action/m-p/692627#M17963</guid>
      <dc:creator>Chiranjeev</dc:creator>
      <dc:date>2024-07-08T11:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: windows ta addon not extracting action</title>
      <link>https://community.splunk.com/t5/Security/windows-ta-addon-not-extracting-action/m-p/692628#M17964</link>
      <description>&lt;P&gt;inputs are enabled for system,app,security logs&amp;nbsp; ,its just action field is not being correctly extracted for event codes&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 11:36:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/windows-ta-addon-not-extracting-action/m-p/692628#M17964</guid>
      <dc:creator>Chiranjeev</dc:creator>
      <dc:date>2024-07-08T11:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: windows ta addon not extracting action</title>
      <link>https://community.splunk.com/t5/Security/windows-ta-addon-not-extracting-action/m-p/692637#M17967</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244593"&gt;@Chiranjeev&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what's the format of your logs?&lt;/P&gt;&lt;P&gt;it's the standard windows or a different one?&lt;/P&gt;&lt;P&gt;I experienced many issues using a concentrator for windows logs.&lt;/P&gt;&lt;P&gt;If the format is different, you shuld reparse them.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 12:25:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/windows-ta-addon-not-extracting-action/m-p/692637#M17967</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-07-08T12:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: windows ta addon not extracting action</title>
      <link>https://community.splunk.com/t5/Security/windows-ta-addon-not-extracting-action/m-p/692648#M17968</link>
      <description>&lt;P&gt;OK. Show us one of your 4624 events found in verbose mode (blur sensitive data if needed).&lt;/P&gt;&lt;P&gt;BTW, looking at my 4624 events I don't see anything that should yield action=success extraction.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 14:57:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/windows-ta-addon-not-extracting-action/m-p/692648#M17968</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-08T14:57:09Z</dc:date>
    </item>
  </channel>
</rss>

