<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to index exported .evt and .evtx files? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-index-exported-evt-and-evtx-files/m-p/294749#M19292</link>
    <description>&lt;P&gt;Hi arechenberg,&lt;/P&gt;

&lt;P&gt;I've resolved this kind of problem by just converting &lt;CODE&gt;.evtx&lt;/CODE&gt; file to &lt;CODE&gt;.txt&lt;/CODE&gt; file, you can do it by opening the &lt;CODE&gt;.evtx&lt;/CODE&gt; file on the Windows Event Viewer on your local machine and save it as Text file or CSV, after converting &lt;CODE&gt;.evtx&lt;/CODE&gt; file to text file or csv you may now ingest in to your splunk. I've provided link on how to save windows event as text file or csv below.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://technet.microsoft.com/en-us/library/cc749339(v=ws.11).aspx"&gt;https://technet.microsoft.com/en-us/library/cc749339(v=ws.11).aspx&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Aug 2017 06:39:49 GMT</pubDate>
    <dc:creator>dantimola</dc:creator>
    <dc:date>2017-08-23T06:39:49Z</dc:date>
    <item>
      <title>How to index exported .evt and .evtx files?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-index-exported-evt-and-evtx-files/m-p/294745#M19288</link>
      <description>&lt;P&gt;I tried the following:&lt;/P&gt;

&lt;P&gt;settings -&amp;gt; Add Data -&amp;gt; Upload Data -&amp;gt; choose xxx.evt as my source and I'm lost at "Set Source Type".  My default source-type shows "preprocess-winevt". I found another source type call Event Log, but when I chose it, the preview is still displayed as hex values. &lt;/P&gt;

&lt;P&gt;I have been directed to &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/Monitorwindowsdata"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Data/Monitorwindowsdata&lt;/A&gt; many times and I don't understand what it is trying to say in the document....how do I index all my exported evt and evtx files?&lt;/P&gt;

&lt;P&gt;I'm on trial version.&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2017 05:48:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-index-exported-evt-and-evtx-files/m-p/294745#M19288</guid>
      <dc:creator>wuming79</dc:creator>
      <dc:date>2017-05-16T05:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to index exported .evt and .evtx files?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-index-exported-evt-and-evtx-files/m-p/294746#M19289</link>
      <description>&lt;P&gt;settings -&amp;gt; data inputs (top right corner) -&amp;gt; local event log collection -&amp;gt; pick the windows logs you want&lt;BR /&gt;
read here more: &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.0/Data/HowtogetWindowsdataintoSplunk"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.0/Data/HowtogetWindowsdataintoSplunk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2017 18:03:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-index-exported-evt-and-evtx-files/m-p/294746#M19289</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-05-16T18:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to index exported .evt and .evtx files?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-index-exported-evt-and-evtx-files/m-p/294747#M19290</link>
      <description>&lt;P&gt;What if i exported .evtx file from other machine and i want to ingest it to our splunk?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 08:09:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-index-exported-evt-and-evtx-files/m-p/294747#M19290</guid>
      <dc:creator>dantimola</dc:creator>
      <dc:date>2017-08-16T08:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to index exported .evt and .evtx files?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-index-exported-evt-and-evtx-files/m-p/294748#M19291</link>
      <description>&lt;P&gt;This answer assumes that Splunk is running on the same machine as the Windows log files.  I believe the intent of the question was how to index *.evtx files that have been exported from a machine as files and then import them into a different machine running Splunk.&lt;/P&gt;

&lt;P&gt;I would like to know an answer to this question as well.  Having a similar problem - I upload the evtx file, file recognized by Splunk as &lt;CODE&gt;preprocess-winevt&lt;/CODE&gt;, complete the import but no data is indexed by Splunk, or very old events (e.g. events from November 2016) are indexed.&lt;/P&gt;

&lt;P&gt;Any help is much appreciated, Andy&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2017 22:09:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-index-exported-evt-and-evtx-files/m-p/294748#M19291</guid>
      <dc:creator>arechenberg</dc:creator>
      <dc:date>2017-08-21T22:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to index exported .evt and .evtx files?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-index-exported-evt-and-evtx-files/m-p/294749#M19292</link>
      <description>&lt;P&gt;Hi arechenberg,&lt;/P&gt;

&lt;P&gt;I've resolved this kind of problem by just converting &lt;CODE&gt;.evtx&lt;/CODE&gt; file to &lt;CODE&gt;.txt&lt;/CODE&gt; file, you can do it by opening the &lt;CODE&gt;.evtx&lt;/CODE&gt; file on the Windows Event Viewer on your local machine and save it as Text file or CSV, after converting &lt;CODE&gt;.evtx&lt;/CODE&gt; file to text file or csv you may now ingest in to your splunk. I've provided link on how to save windows event as text file or csv below.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://technet.microsoft.com/en-us/library/cc749339(v=ws.11).aspx"&gt;https://technet.microsoft.com/en-us/library/cc749339(v=ws.11).aspx&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 06:39:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-index-exported-evt-and-evtx-files/m-p/294749#M19292</guid>
      <dc:creator>dantimola</dc:creator>
      <dc:date>2017-08-23T06:39:49Z</dc:date>
    </item>
  </channel>
</rss>

