<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to pull in Windows Event logs from the Windows PowerShell path in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-in-Windows-Event-logs-from-the-Windows-PowerShell/m-p/584384#M102863</link>
    <description>&lt;P&gt;My inputs.conf was incorrect. I had a / at the end of PowerShell. Removed the / and now it is ingesting properly.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Feb 2022 20:49:26 GMT</pubDate>
    <dc:creator>TheBravoSierra</dc:creator>
    <dc:date>2022-02-09T20:49:26Z</dc:date>
    <item>
      <title>How to pull in Windows Event logs from the Windows PowerShell path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-in-Windows-Event-logs-from-the-Windows-PowerShell/m-p/584351#M102855</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm trying to pull in Windows Event logs from the Windows PowerShell path. This path includes 800s, which I've seen in event viewer so I know they're generated and stored here. I just can't seem to pull anything and I don't see much help on the internet to pulling this path.&lt;/P&gt;
&lt;P&gt;This is my inputs.conf:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[WinEventLog://Windows PowerShell/]&lt;BR /&gt;disabled=0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: This is different from the other PowerShell path where I get my 4103 and 4104 codes:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[WinEventLog://Microsoft-Windows-PowerShell/Operational]&lt;BR /&gt;disabled=0&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any helps is appreciated. Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 19:46:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-in-Windows-Event-logs-from-the-Windows-PowerShell/m-p/584351#M102855</guid>
      <dc:creator>TheBravoSierra</dc:creator>
      <dc:date>2022-02-09T19:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: Read logs from PowerShell</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-in-Windows-Event-logs-from-the-Windows-PowerShell/m-p/584360#M102859</link>
      <description>&lt;P&gt;You have to get a proper path from the Event Log properties.&lt;/P&gt;&lt;P&gt;You seem to have a right one in the second case (Microsoft-Windows-PowerShell/Operational).&lt;/P&gt;&lt;P&gt;But the first one doesn't seem right. Check the properties of this log in Event Viewer and see its Full Name&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 18:07:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-in-Windows-Event-logs-from-the-Windows-PowerShell/m-p/584360#M102859</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-09T18:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull in Windows Event logs from the Windows PowerShell path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-in-Windows-Event-logs-from-the-Windows-PowerShell/m-p/584384#M102863</link>
      <description>&lt;P&gt;My inputs.conf was incorrect. I had a / at the end of PowerShell. Removed the / and now it is ingesting properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 20:49:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-in-Windows-Event-logs-from-the-Windows-PowerShell/m-p/584384#M102863</guid>
      <dc:creator>TheBravoSierra</dc:creator>
      <dc:date>2022-02-09T20:49:26Z</dc:date>
    </item>
  </channel>
</rss>

