<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk onboarding Custom Views from EventViewer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-onboarding-Custom-Views-from-EventViewer/m-p/684140#M114188</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/260210"&gt;@dc17&lt;/a&gt;&amp;nbsp; - You need to give full path like:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[WinEventLog://Microsoft-Windows-Sysmon/Operational]
checkpointInterval = 5
current_only = 0
disabled = 0
start_from = oldest
index = sysmon
sourcetype = WinEventLog:Sysmon&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my case, I can see a folder called &lt;STRONG&gt;Micrsoft&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Windows&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Sysmon&lt;/STRONG&gt; folder. In which I can see &lt;STRONG&gt;Operational&lt;/STRONG&gt;&amp;nbsp;logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to give full path, instead of just&amp;nbsp;&lt;STRONG&gt;MyCustomLog&lt;/STRONG&gt;. Give full path, which you can find from Event Viewer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!!&lt;/P&gt;</description>
    <pubDate>Sat, 13 Apr 2024 06:59:36 GMT</pubDate>
    <dc:creator>VatsalJagani</dc:creator>
    <dc:date>2024-04-13T06:59:36Z</dc:date>
    <item>
      <title>Splunk onboarding Custom Views from EventViewer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-onboarding-Custom-Views-from-EventViewer/m-p/684020#M114175</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am trying to create a custom view (also via Xpath) from EventViewer and later insert it into Splunk via a "&lt;SPAN&gt;WinEventLog&lt;/SPAN&gt;" and leveraging the Windows Addon.&lt;BR /&gt;&lt;BR /&gt;Can it be done using "&lt;SPAN&gt;WinEventLog"&amp;nbsp;&lt;/SPAN&gt;or some other way in inputs.conf as it is for Application/Security/System?&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;[WinEventLog://MyCustomLog]&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;As suggested&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Adding-custom-logs-from-Event-Viewer-stanza/m-p/558616" target="_self"&gt;here&amp;nbsp;&lt;/A&gt;I tried this configuration but no logs were onboarded and it returned no error also in _internal logs.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Has anyone found a custom solution for inserting these newly created custom views from the EventViewer to Splunk?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 12:48:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-onboarding-Custom-Views-from-EventViewer/m-p/684020#M114175</guid>
      <dc:creator>dc17</dc:creator>
      <dc:date>2024-04-12T12:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk onboarding Custom Views from EventViewer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-onboarding-Custom-Views-from-EventViewer/m-p/684140#M114188</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/260210"&gt;@dc17&lt;/a&gt;&amp;nbsp; - You need to give full path like:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[WinEventLog://Microsoft-Windows-Sysmon/Operational]
checkpointInterval = 5
current_only = 0
disabled = 0
start_from = oldest
index = sysmon
sourcetype = WinEventLog:Sysmon&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my case, I can see a folder called &lt;STRONG&gt;Micrsoft&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Windows&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Sysmon&lt;/STRONG&gt; folder. In which I can see &lt;STRONG&gt;Operational&lt;/STRONG&gt;&amp;nbsp;logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to give full path, instead of just&amp;nbsp;&lt;STRONG&gt;MyCustomLog&lt;/STRONG&gt;. Give full path, which you can find from Event Viewer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!!&lt;/P&gt;</description>
      <pubDate>Sat, 13 Apr 2024 06:59:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-onboarding-Custom-Views-from-EventViewer/m-p/684140#M114188</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2024-04-13T06:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk onboarding Custom Views from EventViewer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-onboarding-Custom-Views-from-EventViewer/m-p/684356#M114206</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/260210"&gt;@dc17&lt;/a&gt;&amp;nbsp;- Did the solution work for you?? If so, kindly consider accepting the answer for future Splunk users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 12:28:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-onboarding-Custom-Views-from-EventViewer/m-p/684356#M114206</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2024-04-16T12:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk onboarding Custom Views from EventViewer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-onboarding-Custom-Views-from-EventViewer/m-p/684358#M114207</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for the reply, could you help me find the full path of the file/.evtx from the EventViewer? I could not find any reference from the EventViewer in my CustomViews of a full path where the Logs are stored.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If I recollect this full path, I could perform some tests on the solution you kindly proposed to me,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 12:37:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-onboarding-Custom-Views-from-EventViewer/m-p/684358#M114207</guid>
      <dc:creator>dc17</dc:creator>
      <dc:date>2024-04-16T12:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk onboarding Custom Views from EventViewer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-onboarding-Custom-Views-from-EventViewer/m-p/684371#M114208</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/260210"&gt;@dc17&lt;/a&gt;&amp;nbsp;- I'm not sure what logs you are trying to find in the EventViewer. Is it any known Application logs are you trying to find??&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 14:17:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-onboarding-Custom-Views-from-EventViewer/m-p/684371#M114208</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2024-04-16T14:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk onboarding Custom Views from EventViewer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-onboarding-Custom-Views-from-EventViewer/m-p/684389#M114209</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;I am not looking in any logs specifically because I need to create multiple Custom View and configure them with different &lt;EM&gt;Xpath&lt;/EM&gt; queries.&amp;nbsp; So I am looking on an approach to monitor with &lt;EM&gt;WinEventLog&lt;/EM&gt; these CustomViews.&lt;BR /&gt;&lt;BR /&gt;In the photo an example of CustomView is "&lt;STRONG&gt;Test&lt;/STRONG&gt;" folder.&lt;BR /&gt;But in the path &lt;U&gt;&lt;EM&gt;C:\Windows\System32\winevt\Logs&lt;/EM&gt;&lt;/U&gt; I could not find any reference to this "Test" CustomView.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dc17_1-1713283272111.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30412i96CD1353378590A1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dc17_1-1713283272111.png" alt="dc17_1-1713283272111.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;To recap:&lt;BR /&gt;"&lt;STRONG&gt;Test&lt;/STRONG&gt;" CustomView works fine in the &lt;EM&gt;EventViewer&lt;/EM&gt; and it is updated live with the execution of my query. It contains all the events I am interested (not important which one). However I could not find any path connected to it, where the logs are stored and ready to be collected by a Splunk &lt;EM&gt;WinEventLog&lt;/EM&gt; monitor.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 16:07:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-onboarding-Custom-Views-from-EventViewer/m-p/684389#M114209</guid>
      <dc:creator>dc17</dc:creator>
      <dc:date>2024-04-16T16:07:45Z</dc:date>
    </item>
  </channel>
</rss>

