<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Add-on for Windows in Version 5.0.0 in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423504#M51674</link>
    <description>&lt;P&gt;In the Add-On for Windows, the index declaration has been removed in version &lt;A href="http://docs.splunk.com/Documentation/WindowsAddOn/5.0.0/User/Configuration#Configure_indexes.conf"&gt;5.0.0&lt;/A&gt; , do the inputs have to send to certain indices?&lt;BR /&gt;
In the inputs.conf is no key-value entry for the index. &lt;/P&gt;

&lt;P&gt;The &lt;A href="http://docs.splunk.com/Documentation/DCADAddon"&gt;Splunk Add-on for Microsoft Active Directory&lt;/A&gt; still has an indexes.conf file and in the inputs.conf are also at each Stanza indexes = * entries. Is the MS -AD Add-on not yet updated or is there an error in the add-on for Windows?&lt;/P&gt;</description>
    <pubDate>Sun, 08 Jul 2018 17:16:30 GMT</pubDate>
    <dc:creator>amielke</dc:creator>
    <dc:date>2018-07-08T17:16:30Z</dc:date>
    <item>
      <title>Splunk Add-on for Windows in Version 5.0.0</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423504#M51674</link>
      <description>&lt;P&gt;In the Add-On for Windows, the index declaration has been removed in version &lt;A href="http://docs.splunk.com/Documentation/WindowsAddOn/5.0.0/User/Configuration#Configure_indexes.conf"&gt;5.0.0&lt;/A&gt; , do the inputs have to send to certain indices?&lt;BR /&gt;
In the inputs.conf is no key-value entry for the index. &lt;/P&gt;

&lt;P&gt;The &lt;A href="http://docs.splunk.com/Documentation/DCADAddon"&gt;Splunk Add-on for Microsoft Active Directory&lt;/A&gt; still has an indexes.conf file and in the inputs.conf are also at each Stanza indexes = * entries. Is the MS -AD Add-on not yet updated or is there an error in the add-on for Windows?&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jul 2018 17:16:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423504#M51674</guid>
      <dc:creator>amielke</dc:creator>
      <dc:date>2018-07-08T17:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Windows in Version 5.0.0</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423505#M51675</link>
      <description>&lt;P&gt;There is a H*U*G*E risk with v5.0 of this app that is highly likely to cause breakage of your non-TA field extractions.  There is something different about how it handles &lt;CODE&gt;source&lt;/CODE&gt; and &lt;CODE&gt;sourcetypes&lt;/CODE&gt; but unfortunately I did not take enough time to diagnose it.  It caused a ton of our custom field extractions not to work so we downgraded.  The app's documentation page does not indicate anything that would have caused us concern about upgrading, which is also a concern.  Hopefully the docs page will get an update with an appropriate explanation and warning.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:21:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423505#M51675</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-09-29T20:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Windows in Version 5.0.0</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423506#M51676</link>
      <description>&lt;P&gt;It's right here in the docs: &lt;A href="http://docs.splunk.com/Documentation/WindowsAddOn/5.0.0/User/Upgrade#Source_and_sourcetype_changes_for_WinEventLog_data"&gt;http://docs.splunk.com/Documentation/WindowsAddOn/5.0.0/User/Upgrade#Source_and_sourcetype_changes_for_WinEventLog_data&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jul 2018 21:10:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423506#M51676</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2018-07-08T21:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Windows in Version 5.0.0</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423507#M51677</link>
      <description>&lt;P&gt;And no mention in the release notes as per your discussion on the documentation page!&lt;/P&gt;

&lt;P&gt;Since the documentation pages don't have a "show differences" button between versions it should really be on the release notes.&lt;BR /&gt;
That said, if I could show differences between documentation versions it would be incredibly useful &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jul 2018 23:01:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423507#M51677</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2018-07-08T23:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Windows in Version 5.0.0</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423508#M51678</link>
      <description>&lt;P&gt;@amielke The Windows Addon 5.0.0 document stats that indexes.conf and its related configurations in inputs.conf/wmi.conf etc have been removed and thus it's not an error. &lt;A href="http://docs.splunk.com/Documentation/WindowsAddOn/5.0.0/User/Configuration#Configure_indexes.conf"&gt;http://docs.splunk.com/Documentation/WindowsAddOn/5.0.0/User/Configuration#Configure_indexes.conf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The upgrade steps are clearly mentioned in &lt;A href="http://docs.splunk.com/Documentation/WindowsAddOn/5.0.0/User/Upgrade#Upgrade_from_a_previous_version_of_Windows_to_5.0.x"&gt;http://docs.splunk.com/Documentation/WindowsAddOn/5.0.0/User/Upgrade#Upgrade_from_a_previous_version_of_Windows_to_5.0.x&lt;/A&gt; .&lt;/P&gt;

&lt;P&gt;While for active directory addon,we can see on splunkbase, &lt;A href="https://splunkbase.splunk.com/app/3207/"&gt;https://splunkbase.splunk.com/app/3207/&lt;/A&gt; that it was released in 2016 and hence looks like it is not yet updated.&lt;/P&gt;

&lt;P&gt;I followed the upgrade steps for index configuration for Windows 5.0.0 Addon. Everything worked fine for me. &lt;/P&gt;

&lt;P&gt;Please revert back if you have any questions. Will be happy to help.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 09:46:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423508#M51678</guid>
      <dc:creator>bhargavnariyani</dc:creator>
      <dc:date>2018-07-09T09:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Windows in Version 5.0.0</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423509#M51679</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/1406"&gt;@woodcock&lt;/a&gt; Can you please explain in detail like with an example which kind of custom extractions broke for you? &lt;BR /&gt;
As mentioned by &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/172708"&gt;@martin_mueller&lt;/a&gt;, the documentation is available which explains the changes to WinEventLog source and sourcetypes in v5.0.0. &lt;BR /&gt;
Just pasting the link again.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/WindowsAddOn/5.0.0/User/Upgrade#WinEventLog_extraction_changes" target="_blank"&gt;http://docs.splunk.com/Documentation/WindowsAddOn/5.0.0/User/Upgrade#WinEventLog_extraction_changes&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I would suggest you to have a look at it again, if you face any issues after that I would be happy to help. Please have a look at documentation and revert back if you face any issues related to extractions that doesn't work for you. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:18:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423509#M51679</guid>
      <dc:creator>bhargavnariyani</dc:creator>
      <dc:date>2020-09-29T20:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Windows in Version 5.0.0</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423510#M51680</link>
      <description>&lt;P&gt;Yes, I missed the upgrade section and still believe that a shout-out to that section in the Release Notes is warranted, something like &lt;CODE&gt;There are significant changes to the plumbing that may cause breakage when upgrading to older releases, see the upgrade section for details.&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 13:22:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423510#M51680</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-07-09T13:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Windows in Version 5.0.0</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423511#M51681</link>
      <description>&lt;P&gt;@bhargavnariyani: Yes the documentation read fine and is clear, but if I start to setup the Splunk App for windows infrastructure, the app expected version 4.8.4. This is not accept in my eyes &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;That means for me I cannot use the Splunk Add-On for Windows in version 5.0.0, because the Splunk App for Windows infrastructure in version 1.4.4 does not accept the new version. &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5325iE61872C0A1A897EA/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 14:41:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423511#M51681</guid>
      <dc:creator>amielke</dc:creator>
      <dc:date>2018-07-25T14:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Windows in Version 5.0.0</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423512#M51682</link>
      <description>&lt;P&gt;@ amielke , i have recently installed the Splunk App for Windows Infrastructure and i encountered the same red X mark during the pre-requisites check. I had to install the TA_for_Windows v4.8.4 as required by this app.&lt;BR /&gt;
The v5.0.0 is not compatible with the APP for Win Infrastructure.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:36:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423512#M51682</guid>
      <dc:creator>neerajshah81</dc:creator>
      <dc:date>2020-09-29T20:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Windows in Version 5.0.0</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423513#M51683</link>
      <description>&lt;P&gt;@amielke Agree that's an blocker as of now, that Windows 5.0.0 can't be used with Winfra 1.4.4. But I guess It will be short term. As Windows 5.0.0 is released now, soon a compatible Winfra version should be released. Hope that helps.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 17:59:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-in-Version-5-0-0/m-p/423513#M51683</guid>
      <dc:creator>bhargavnariyani</dc:creator>
      <dc:date>2018-07-26T17:59:57Z</dc:date>
    </item>
  </channel>
</rss>

