<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Find enabled windows inputs by SPL query? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Find-enabled-windows-inputs-by-SPL-query/m-p/648556#M79353</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;It's quite easy to find which monitor inputs are activated via host's inputs.conf by queuing those from UF's _internal log. But how I can check same for Windows additional components like&amp;nbsp;&lt;SPAN&gt;WinRegMon or&amp;nbsp;&lt;/SPAN&gt;admon?&lt;/P&gt;&lt;P&gt;Basically I can see all known possible win monitoring components by&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=* sourcetype=splunkd source=*splunkd.log component=ModularInputs&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But how to find which are activated, when I have to look those from hundreds of nodes over long period like 30 days?&lt;/P&gt;&lt;P&gt;I hope to get something like this&lt;/P&gt;&lt;TABLE width="727px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="40px"&gt;_time&lt;/TD&gt;&lt;TD width="52.78125px"&gt;HOST&lt;/TD&gt;&lt;TD width="105.875px"&gt;&lt;SPAN&gt;WinEventLog&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="573.21875px"&gt;&amp;lt;enabled or even which logs are enabled&amp;gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;_time&lt;/TD&gt;&lt;TD width="52.78125px"&gt;HOST&lt;/TD&gt;&lt;TD width="105.875px"&gt;batch&lt;/TD&gt;&lt;TD width="573.21875px"&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\run\splunk\search_telemetry\*search_telemetry.json&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\spool\splunk&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\spool\splunk\...stash_hec&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\spool\splunk\...stash_new&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\spool\splunk\tracker.log*&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;_time&lt;/TD&gt;&lt;TD&gt;HOST&lt;/TD&gt;&lt;TD&gt;monitor&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\etc\splunk.version&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\log\splunk&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\log\splunk\configuration_change.log&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\log\splunk\license_usage_summary.log&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\log\splunk\metrics.log&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\log\splunk\splunk_instrumentation_cloud.log*&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\log\splunk\splunkd.log&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\log\watchdog\watchdog.log*&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jun 2023 14:57:12 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2023-06-28T14:57:12Z</dc:date>
    <item>
      <title>Find enabled windows inputs by SPL query?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Find-enabled-windows-inputs-by-SPL-query/m-p/648556#M79353</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;It's quite easy to find which monitor inputs are activated via host's inputs.conf by queuing those from UF's _internal log. But how I can check same for Windows additional components like&amp;nbsp;&lt;SPAN&gt;WinRegMon or&amp;nbsp;&lt;/SPAN&gt;admon?&lt;/P&gt;&lt;P&gt;Basically I can see all known possible win monitoring components by&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=* sourcetype=splunkd source=*splunkd.log component=ModularInputs&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But how to find which are activated, when I have to look those from hundreds of nodes over long period like 30 days?&lt;/P&gt;&lt;P&gt;I hope to get something like this&lt;/P&gt;&lt;TABLE width="727px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="40px"&gt;_time&lt;/TD&gt;&lt;TD width="52.78125px"&gt;HOST&lt;/TD&gt;&lt;TD width="105.875px"&gt;&lt;SPAN&gt;WinEventLog&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="573.21875px"&gt;&amp;lt;enabled or even which logs are enabled&amp;gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;_time&lt;/TD&gt;&lt;TD width="52.78125px"&gt;HOST&lt;/TD&gt;&lt;TD width="105.875px"&gt;batch&lt;/TD&gt;&lt;TD width="573.21875px"&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\run\splunk\search_telemetry\*search_telemetry.json&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\spool\splunk&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\spool\splunk\...stash_hec&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\spool\splunk\...stash_new&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\spool\splunk\tracker.log*&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;_time&lt;/TD&gt;&lt;TD&gt;HOST&lt;/TD&gt;&lt;TD&gt;monitor&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\etc\splunk.version&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\log\splunk&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\log\splunk\configuration_change.log&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\log\splunk\license_usage_summary.log&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\log\splunk\metrics.log&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\log\splunk\splunk_instrumentation_cloud.log*&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\log\splunk\splunkd.log&lt;/DIV&gt;&lt;DIV class=""&gt;//$SPLUNK_HOME\var\log\watchdog\watchdog.log*&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 14:57:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Find-enabled-windows-inputs-by-SPL-query/m-p/648556#M79353</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-06-28T14:57:12Z</dc:date>
    </item>
  </channel>
</rss>

