<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ingesting offline Windows Event logs from different systems in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-offline-Windows-Event-logs-from-different-systems/m-p/649421#M110393</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;If I understood right you have those events on .evxt files? Is so you should create separate inputs.conf for those. There are couple of posts where this has explained&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://invictus-ir.medium.com/importing-windows-event-log-files-into-splunk-9ae1beb0bea4" target="_blank" rel="noopener"&gt;https://invictus-ir.medium.com/importing-windows-event-log-files-into-splunk-9ae1beb0bea4&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.cloud-response.com/2019/07/importing-windows-event-log-files-into.html" target="_blank" rel="noopener"&gt;https://www.cloud-response.com/2019/07/importing-windows-event-log-files-into.html&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Key word seems to be&amp;nbsp;&lt;SPAN&gt;sourcetype="&lt;/SPAN&gt;&lt;I&gt;preprocess-winevt".&lt;/I&gt;&lt;/P&gt;&lt;P&gt;If you have those files on linux there is some additional tools which your are needing to read/index correctly into splunk.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Thu, 06 Jul 2023 08:57:54 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2023-07-06T08:57:54Z</dc:date>
    <item>
      <title>Ingesting offline Windows Event logs from different systems</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-offline-Windows-Event-logs-from-different-systems/m-p/649419#M110392</link>
      <description>&lt;P&gt;I am trying to use a Universal Forwarder to get a load of windows event logs that I need to analyse into Splunk. The event logs are from about 7 different systems and are all located on my local laptop in a folder.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried adding the folder into the inputs.conf file and setting the sourcetype to WinEventLog, but once the data is in, the individual events are not being extracted. Rather the entire file is being passed as one event and all I can see are the headers for each Event Log.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is someone able to help me with this please?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I should probably state that I am using a Splunk Cloud instance and do not have a deployment server - I need to go straight from my laptop to the Splunk Cloud instance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 08:47:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingesting-offline-Windows-Event-logs-from-different-systems/m-p/649419#M110392</guid>
      <dc:creator>KP3</dc:creator>
      <dc:date>2023-07-06T08:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: Ingesting offline Windows Event logs from different systems</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-offline-Windows-Event-logs-from-different-systems/m-p/649421#M110393</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;If I understood right you have those events on .evxt files? Is so you should create separate inputs.conf for those. There are couple of posts where this has explained&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://invictus-ir.medium.com/importing-windows-event-log-files-into-splunk-9ae1beb0bea4" target="_blank" rel="noopener"&gt;https://invictus-ir.medium.com/importing-windows-event-log-files-into-splunk-9ae1beb0bea4&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.cloud-response.com/2019/07/importing-windows-event-log-files-into.html" target="_blank" rel="noopener"&gt;https://www.cloud-response.com/2019/07/importing-windows-event-log-files-into.html&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Key word seems to be&amp;nbsp;&lt;SPAN&gt;sourcetype="&lt;/SPAN&gt;&lt;I&gt;preprocess-winevt".&lt;/I&gt;&lt;/P&gt;&lt;P&gt;If you have those files on linux there is some additional tools which your are needing to read/index correctly into splunk.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 08:57:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingesting-offline-Windows-Event-logs-from-different-systems/m-p/649421#M110393</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-07-06T08:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: Ingesting offline Windows Event logs from different systems</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-offline-Windows-Event-logs-from-different-systems/m-p/649515#M110399</link>
      <description>&lt;P&gt;Thank you! That has worked.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 15:22:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingesting-offline-Windows-Event-logs-from-different-systems/m-p/649515#M110399</guid>
      <dc:creator>KP3</dc:creator>
      <dc:date>2023-07-06T15:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: Ingesting offline Windows Event logs from different systems</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-offline-Windows-Event-logs-from-different-systems/m-p/709565#M117225</link>
      <description>&lt;P&gt;A small update to these link (the former is a repost of the latter). The former link/document was moved to&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://www.invictus-ir.com/news/importing-windows-event-log-files-into-splunk" target="_self"&gt;https://www.invictus-ir.com/news/importing-windows-event-log-files-into-splunk&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 23 Jan 2025 07:38:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingesting-offline-Windows-Event-logs-from-different-systems/m-p/709565#M117225</guid>
      <dc:creator>rvany</dc:creator>
      <dc:date>2025-01-23T07:38:52Z</dc:date>
    </item>
  </channel>
</rss>

