<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is Splunk not indexing? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613642#M106191</link>
    <description>&lt;P&gt;I have done this before.&amp;nbsp; I got everything set up and working then another employee took over the task.&amp;nbsp; They then moved and took the computer with them.&amp;nbsp; That employee recently moved to another position and UPS "lost" the computer, so I am now trying to get it set up on a new machine.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do remember when configuring the previous box I used&amp;nbsp;&lt;SPAN&gt;WinEventLog somewhere in the process.&amp;nbsp; I thought it was in the Source Type under operating system but all I see there now is windows_snare_syslog and that does not seem to work either.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Sep 2022 16:50:11 GMT</pubDate>
    <dc:creator>rockb</dc:creator>
    <dc:date>2022-09-19T16:50:11Z</dc:date>
    <item>
      <title>Why is Splunk not indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613632#M106188</link>
      <description>&lt;P&gt;I am trying to use Splunk to review windows logs that were exported from machines that are not on a network.&amp;nbsp; I have copied the .evtx files to my Splunk machine.&lt;/P&gt;
&lt;P&gt;Fresh install of Splunk 9.0.1&lt;/P&gt;
&lt;P&gt;Below is the process I used to try to get the events indexed.&amp;nbsp; I think this is the same process I have used in the past but for some reason no events are indexed.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Settings --&amp;gt; New Index&lt;BR /&gt;2. Enter Name for index&lt;BR /&gt;3. Save&lt;BR /&gt;4. Settings --&amp;gt; Data Inputs&lt;BR /&gt;5. Files and Directories&lt;BR /&gt;6. New Local File and Directory&lt;BR /&gt;7. Input Path of top level folder containing logs&lt;BR /&gt;8. Select Continuously Monitor&lt;BR /&gt;9. Next&lt;BR /&gt;10. Source Type: Automatic&lt;BR /&gt;11. App Context: Search and reporting&lt;BR /&gt;12. Select Constant Value&lt;BR /&gt;13. Host field name:*&lt;BR /&gt;14. Select Index Created in steps 1- 3&lt;BR /&gt;15. Review&lt;BR /&gt;16. Start Searching&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The search results in 0 events listed.&amp;nbsp; I delete everything from the search box except index="nameofindex" and still there are no events listed.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 15:50:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613632#M106188</guid>
      <dc:creator>rockb</dc:creator>
      <dc:date>2022-09-19T15:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613641#M106190</link>
      <description>&lt;P&gt;Splunk can't read Windows event logs using a monitor input.&amp;nbsp; The usual method is via a WinEventLog input, but that probably won't work with transferred files since WinEventLog expects to get data directly from the local Windows server.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 16:38:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613641#M106190</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-09-19T16:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613642#M106191</link>
      <description>&lt;P&gt;I have done this before.&amp;nbsp; I got everything set up and working then another employee took over the task.&amp;nbsp; They then moved and took the computer with them.&amp;nbsp; That employee recently moved to another position and UPS "lost" the computer, so I am now trying to get it set up on a new machine.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do remember when configuring the previous box I used&amp;nbsp;&lt;SPAN&gt;WinEventLog somewhere in the process.&amp;nbsp; I thought it was in the Source Type under operating system but all I see there now is windows_snare_syslog and that does not seem to work either.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 16:50:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613642#M106191</guid>
      <dc:creator>rockb</dc:creator>
      <dc:date>2022-09-19T16:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613643#M106192</link>
      <description>&lt;P&gt;The sourcetype to use is 'wineventlog'.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 17:18:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613643#M106192</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-09-19T17:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613644#M106193</link>
      <description>&lt;P&gt;I'm not sure but I think I read somewhere that splunk was able (at least some time ago) to read evt files (not sure about evtx). One caveat - it must have been a windows splunk version - it probably used some system library calls to process the file.&lt;/P&gt;&lt;P&gt;I'm not however sure if the possibility still exists since I haven't seen a windows-based splunk server for a loooooong time.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 17:52:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613644#M106193</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-09-19T17:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613647#M106195</link>
      <description>&lt;P&gt;&lt;SPAN&gt;wineventlog was not found but that did get me there.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The correct string is "preprocess-winevt".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is indexing now.&amp;nbsp; Thank you .&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 18:02:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613647#M106195</guid>
      <dc:creator>rockb</dc:creator>
      <dc:date>2022-09-19T18:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613704#M106203</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234313"&gt;@rockb&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;to ingest wineventlogs you have to use the wineventlog connector created by Splunk because windows eventlogs are encrypted.&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;said you have to use a different input option: [Settings -- Data inputs -- Local event log Collection]&amp;nbsp; and automatically the correct sourcetype will associated to the logs: wineventlog:security,&amp;nbsp;wineventlog:application,&amp;nbsp;wineventlog:system.&lt;/P&gt;&lt;P&gt;My hint is to use a different approach:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;downaload the Splunk TA_Windows from Splunkbase (&lt;A href="https://splunkbase.splunk.com/app/742/)" target="_blank"&gt;https://splunkbase.splunk.com/app/742/),&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;copy the inputs.conf from the default to local folder,&lt;/LI&gt;&lt;LI&gt;enable the stanzas you need (disabled=0),&lt;/LI&gt;&lt;LI&gt;upload the App in your Splunk environment or deploy to your Splunk Forwarder.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In this way, you have a more organized data input.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 06:38:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613704#M106203</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-20T06:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613723#M106206</link>
      <description>&lt;P&gt;evtx files are _not_ encrypted. You can move your files around and you can import them into another machine and whatnot. And you don't have to provide any secrets in doing so. So they are not encrypted. They are however encoded so they are not in a plain text format and are thus useless for direct importing with a monitor input.&lt;/P&gt;&lt;P&gt;One could try importing the files into event viewer and setting an Event Log input with the destination log name. Might work but I haven't tried it myself.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 08:00:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-indexing/m-p/613723#M106206</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-09-20T08:00:44Z</dc:date>
    </item>
  </channel>
</rss>

