<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Logs not coming from Windows Defender in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305502#M36429</link>
    <description>&lt;P&gt;Hi&lt;BR /&gt;
I have running Windows Defender and want to collect logs to Splunk. &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Windows Defender that running on my host Windows 10 Enterprise LTSB;&lt;/LI&gt;
&lt;LI&gt;Splunk 7.0 that collect logs local from my host;&lt;/LI&gt;
&lt;LI&gt;TA for Microsoft Windows Dedender;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Logs not collected.&lt;BR /&gt;
What should I do to fix it? I have no idea.&lt;/P&gt;</description>
    <pubDate>Sat, 13 Jan 2018 15:36:22 GMT</pubDate>
    <dc:creator>test_qweqwe</dc:creator>
    <dc:date>2018-01-13T15:36:22Z</dc:date>
    <item>
      <title>Logs not coming from Windows Defender</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305502#M36429</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
I have running Windows Defender and want to collect logs to Splunk. &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Windows Defender that running on my host Windows 10 Enterprise LTSB;&lt;/LI&gt;
&lt;LI&gt;Splunk 7.0 that collect logs local from my host;&lt;/LI&gt;
&lt;LI&gt;TA for Microsoft Windows Dedender;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Logs not collected.&lt;BR /&gt;
What should I do to fix it? I have no idea.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 15:36:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305502#M36429</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2018-01-13T15:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not coming from Windows Defender</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305503#M36430</link>
      <description>&lt;P&gt;Did you deploy the add-on to the Windows host you wish to get the logs from?&lt;/P&gt;

&lt;P&gt;Ideally, you would do this from the Forwarder Manager (Settings-&amp;gt;Forwarder Management).&lt;BR /&gt;
Copy the add-on from $SPLUNK/etc/apps to $SPLUNK/etc/deploy-apps.&lt;BR /&gt;
Create a new folder "local" in $SPLUNK/etc/deploy-apps//&lt;BR /&gt;
Copy the inputs.conf from the "default" folder to "local" (the one you just created)&lt;BR /&gt;
Change "disabled = true" to "disabled = false"&lt;/P&gt;

&lt;P&gt;Verify that the TA_microsoft-windefender folder is on the host you wish to get that data from and then you should be good to go.&lt;/P&gt;

&lt;P&gt;Restart the forwarder service (services.msc) for good measure.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 15:50:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305503#M36430</guid>
      <dc:creator>mjeffery_splunk</dc:creator>
      <dc:date>2018-01-13T15:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not coming from Windows Defender</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305504#M36431</link>
      <description>&lt;P&gt;I did it all and it's not helped.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 15:55:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305504#M36431</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2018-01-13T15:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not coming from Windows Defender</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305505#M36432</link>
      <description>&lt;P&gt;Bring up the Event Viewer on the Windows box you're trying to get those logs from and verify that it is indeed logging the events under "Applications and Services Logs"&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 21:42:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305505#M36432</guid>
      <dc:creator>mjeffery_splunk</dc:creator>
      <dc:date>2018-01-13T21:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not coming from Windows Defender</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305506#M36433</link>
      <description>&lt;P&gt;So, if i generating new event (downloaded poor virus that windefender detect) it's sends logs. One problem is resolved \o/&lt;/P&gt;

&lt;P&gt;But another problem, how to collect all logs from Windefender? &lt;BR /&gt;
Not only new. All from beginning to now. And yes in Event Viewer in &lt;CODE&gt;Microsoft-Windows-Windows Defender/Operational&lt;/CODE&gt; there are many logs.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 21:57:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305506#M36433</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2018-01-13T21:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not coming from Windows Defender</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305507#M36434</link>
      <description>&lt;P&gt;My config&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog://Microsoft-Windows-Windows Defender/Operational]
index = windefender
disabled = false
start_from = oldest
current_only = 0
renderXml = 1
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 13 Jan 2018 22:10:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305507#M36434</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2018-01-13T22:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not coming from Windows Defender</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305508#M36435</link>
      <description>&lt;P&gt;This works for me:&lt;BR /&gt;
[WinEventLog://Microsoft-Windows-Windows Defender/Operational]&lt;BR /&gt;
index = windefender&lt;BR /&gt;
disabled = false&lt;BR /&gt;
renderXml = 1&lt;/P&gt;

&lt;P&gt;I confirm logs coming into Splunk for index=windefender with that input. Confirm that your Windows Defender log location is correct for your system.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 23:23:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305508#M36435</guid>
      <dc:creator>pdoconnell</dc:creator>
      <dc:date>2018-01-13T23:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not coming from Windows Defender</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305509#M36436</link>
      <description>&lt;P&gt;Hi!&lt;BR /&gt;
In my previous comment I said that logs coming, but only new. I need historical (old) and new logs.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 23:28:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305509#M36436</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2018-01-13T23:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not coming from Windows Defender</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305510#M36437</link>
      <description>&lt;P&gt;It looks like the start_from and current_only stanzas dont appear anymore in the &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.1/Admin/Inputsconf" target="_blank"&gt;inputs.conf definition&lt;/A&gt;. Maybe it is no longer supported?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:43:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305510#M36437</guid>
      <dc:creator>pdoconnell</dc:creator>
      <dc:date>2020-09-29T17:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not coming from Windows Defender</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305511#M36438</link>
      <description>&lt;P&gt;Maybe, but how me collect all logs of windefender that i have on my PC? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jan 2018 01:43:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Logs-not-coming-from-Windows-Defender/m-p/305511#M36438</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2018-01-14T01:43:33Z</dc:date>
    </item>
  </channel>
</rss>

