<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows event log fields are not extracted properly in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/539441#M64848</link>
    <description>&lt;P&gt;In some instances,&amp;nbsp;&amp;nbsp;Windows event log fields are not extracted properly but in others they are extracted properly.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Feb 2021 09:44:45 GMT</pubDate>
    <dc:creator>sh_tavousi</dc:creator>
    <dc:date>2021-02-11T09:44:45Z</dc:date>
    <item>
      <title>Windows event log fields are not extracted properly</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/539441#M64848</link>
      <description>&lt;P&gt;In some instances,&amp;nbsp;&amp;nbsp;Windows event log fields are not extracted properly but in others they are extracted properly.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 09:44:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/539441#M64848</guid>
      <dc:creator>sh_tavousi</dc:creator>
      <dc:date>2021-02-11T09:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: Windows event log fields are not extracted properly</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/539521#M64851</link>
      <description>&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;Hi my name is Yeasuh and I am a Community Content Specialist for Splunk Answers. Thank you for participating in the Splunk Answers community. &lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;To increase your chances of getting help from the community, please make sure that the title/subject line you use is descriptive and explains the question with enough detail. When posting questions in the future, please provide more information and context.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 16:33:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/539521#M64851</guid>
      <dc:creator>yeasuh</dc:creator>
      <dc:date>2021-02-11T16:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: Windows event log fields are not extracted properly</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/539523#M64852</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231307"&gt;@sh_tavousi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;could you describe better your need?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;what do you mean with instances?&lt;/LI&gt;&lt;LI&gt;are you using the Splunk_TA_Windows?&lt;/LI&gt;&lt;LI&gt;which fields aren't extracted properly?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 16:42:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/539523#M64852</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-11T16:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: Windows event log fields are not extracted properly</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/539782#M64865</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;When I search source="wineventlog:security" or&amp;nbsp;"wineventlog:system" in some hosts in search head,&amp;nbsp;results are not extracted. They are raw but others are extracted properly. I have installed UF on hosts and also I have used&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Splunk_TA_Windows.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I've looked at a lot of conf files and no luck as of yet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Shohre&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2021 05:20:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/539782#M64865</guid>
      <dc:creator>sh_tavousi</dc:creator>
      <dc:date>2021-02-13T05:20:13Z</dc:date>
    </item>
    <item>
      <title>Re: Windows event log fields are not extracted properly</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/539832#M64869</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231307"&gt;@sh_tavousi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;did you installed Splunk_TA_windows only on Forwarders or also on Search Heads?&lt;/P&gt;&lt;P&gt;Which fields aren't recognized?&lt;/P&gt;&lt;P&gt;Did you run the searches always in Verbose Mode?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 14 Feb 2021 08:50:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/539832#M64869</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-14T08:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: Windows event log fields are not extracted properly</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/540191#M64893</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Yes, I installed&amp;nbsp;&lt;SPAN&gt;Splunk_TA_windows&amp;nbsp; on Forwarders and on Search Heads.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In WinEventLog&amp;nbsp; :security and&amp;nbsp;WinEventLog:system,&amp;nbsp; all fields are not extracted like Event Code, Event ID, Account Name and ... . However other hosts do not have any problems and I have all field extracted.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I do not run&amp;nbsp;searches&amp;nbsp; in Verbose Mode. My search is " index=main source=WinEventLog&amp;nbsp; :security" and then results in some hosts are not extracted.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Shohre&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 06:42:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/540191#M64893</guid>
      <dc:creator>sh_tavousi</dc:creator>
      <dc:date>2021-02-17T06:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: Windows event log fields are not extracted properly</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/540194#M64894</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231307"&gt;@sh_tavousi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;it's a very strange behavior!&lt;/P&gt;&lt;P&gt;please some last checks:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;logs recognized and not recognized are in the same language? I had some problem having logs from some server in Italian instead of English.&lt;/LI&gt;&lt;LI&gt;sourcetype is the same in both logs?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 07:40:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/540194#M64894</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-17T07:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: Windows event log fields are not extracted properly</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/540702#M64920</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;Giuseppe,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes, logs recogni&lt;/SPAN&gt;&lt;SPAN&gt;zed and not recognized are in the same language.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sourcetype is note the same in both logs. In extracted logs sourcetype=wineventlog but in not recognized logs sourcetype=xmlwineventlog.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Shohre.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Feb 2021 06:06:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/540702#M64920</guid>
      <dc:creator>sh_tavousi</dc:creator>
      <dc:date>2021-02-21T06:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Windows event log fields are not extracted properly</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/540775#M64922</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231307"&gt;@sh_tavousi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;this is the problem: field extractions are usually related to sourcetype, if you have a different sourcetype, surely you haven't the same extractions.&lt;/P&gt;&lt;P&gt;So you have two ways to solve the problem:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;override the sourcetype value,&lt;/LI&gt;&lt;LI&gt;duplicate windows extraction for&amp;nbsp;&lt;SPAN&gt;xmlwineventlog.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;the first solution is easier: you have to change the sourcetype assign in input or add an overriding on Indexers or (when present) on Heavy Forwarders (for more infos see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Advancedsourcetypeoverrides" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Advancedsourcetypeoverrides&lt;/A&gt;&amp;nbsp;).&lt;/P&gt;&lt;P&gt;If you want to maintain a different sourcetype, you have to create all the extractions you need using regexes.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 07:16:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/540775#M64922</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-22T07:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Windows event log fields are not extracted properly</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/542692#M65054</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231307"&gt;@sh_tavousi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Good for You.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Mar 2021 16:02:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-event-log-fields-are-not-extracted-properly/m-p/542692#M65054</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-06T16:02:18Z</dc:date>
    </item>
  </channel>
</rss>

