<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WinEventLog vs XmlWinEventLog in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-vs-XmlWinEventLog/m-p/676925#M113208</link>
    <description>&lt;P&gt;First thing to check is of course btool&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool inputs list --debug&lt;/LI-CODE&gt;&lt;P&gt;for the respective inputs.&amp;nbsp; If it shows renderXml set to false, for those inputs, then some other setting is overriding the setting you are trying to apply.&amp;nbsp; Adding the --debug flag lets you know which file provides the winning setting, so you can figure out where it is coming from.&lt;/P&gt;</description>
    <pubDate>Thu, 08 Feb 2024 04:39:57 GMT</pubDate>
    <dc:creator>mmccul</dc:creator>
    <dc:date>2024-02-08T04:39:57Z</dc:date>
    <item>
      <title>WinEventLog vs XmlWinEventLog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-vs-XmlWinEventLog/m-p/674694#M112920</link>
      <description>&lt;P&gt;Good Morning,&lt;/P&gt;&lt;P&gt;I am running into an issue where my two newest Server 2022 endpoints have events that are showing up non-XML, whereas all my other endpoints are outputting in XML. I have renderXml=true in the inputs.conf and the inputs.conf files in the Splunk_TA_windows are the same for each endpoint. I can't find the difference causing this.&lt;/P&gt;&lt;P&gt;One thing I have learned through this is that I may prefer non-XML so if these two endpoints are not respecting renderXml=true, how do I know all the others will respect the false value to match them all up? Is there somewhere overriding this? I have not edited any \etc\system\default\inputs.conf files. They're all in local or an app.&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;&lt;P&gt;Edit: I am on Splunk Cloud.&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 15:47:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-vs-XmlWinEventLog/m-p/674694#M112920</guid>
      <dc:creator>thebankitgui</dc:creator>
      <dc:date>2024-01-18T15:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog vs XmlWinEventLog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-vs-XmlWinEventLog/m-p/676925#M113208</link>
      <description>&lt;P&gt;First thing to check is of course btool&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool inputs list --debug&lt;/LI-CODE&gt;&lt;P&gt;for the respective inputs.&amp;nbsp; If it shows renderXml set to false, for those inputs, then some other setting is overriding the setting you are trying to apply.&amp;nbsp; Adding the --debug flag lets you know which file provides the winning setting, so you can figure out where it is coming from.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 04:39:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-vs-XmlWinEventLog/m-p/676925#M113208</guid>
      <dc:creator>mmccul</dc:creator>
      <dc:date>2024-02-08T04:39:57Z</dc:date>
    </item>
  </channel>
</rss>

