<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Legacy windows (XP, Server 2000) log onboarding to Splunk (without UF) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Legacy-windows-XP-Server-2000-log-onboarding-to-Splunk-without/m-p/754074#M119698</link>
    <description>&lt;P&gt;If you really need to use those and need logs into splunk, I suppose that you need to do some scripting or programming for that. Just read those logs with your script/program and then send those via Splunk HEC into indexers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://dev.splunk.com/enterprise/docs/devtools/httpeventcollector/" target="_blank"&gt;https://dev.splunk.com/enterprise/docs/devtools/httpeventcollector/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;told more how to use HEC.&lt;/P&gt;</description>
    <pubDate>Wed, 08 Oct 2025 07:41:32 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2025-10-08T07:41:32Z</dc:date>
    <item>
      <title>Legacy windows (XP, Server 2000) log onboarding to Splunk (without UF)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Legacy-windows-XP-Server-2000-log-onboarding-to-Splunk-without/m-p/754071#M119697</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi team,&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Is there any way to onboard legacy windows (XP, Server 2000) logs to Splunk, without UF? Specifically non domain devices.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 05:20:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Legacy-windows-XP-Server-2000-log-onboarding-to-Splunk-without/m-p/754071#M119697</guid>
      <dc:creator>Anit_Mathew</dc:creator>
      <dc:date>2025-10-08T05:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy windows (XP, Server 2000) log onboarding to Splunk (without UF)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Legacy-windows-XP-Server-2000-log-onboarding-to-Splunk-without/m-p/754074#M119698</link>
      <description>&lt;P&gt;If you really need to use those and need logs into splunk, I suppose that you need to do some scripting or programming for that. Just read those logs with your script/program and then send those via Splunk HEC into indexers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://dev.splunk.com/enterprise/docs/devtools/httpeventcollector/" target="_blank"&gt;https://dev.splunk.com/enterprise/docs/devtools/httpeventcollector/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;told more how to use HEC.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 07:41:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Legacy-windows-XP-Server-2000-log-onboarding-to-Splunk-without/m-p/754074#M119698</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-10-08T07:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy windows (XP, Server 2000) log onboarding to Splunk (without UF)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Legacy-windows-XP-Server-2000-log-onboarding-to-Splunk-without/m-p/754075#M119699</link>
      <description>&lt;P&gt;1. Welcome to the Archaeology department &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;2. Do you want to onboard static evt file or do you by any chance have a still running w2k/wxp instances and want to onboard "running logs"?&lt;/P&gt;&lt;P&gt;Static files might work with windows-based UF (but I never remember the right configuration for it - you have to search).&lt;/P&gt;&lt;P&gt;If you have a still operational ancient windows boxes... there are the same general options with any more modern windows but they might be more tricky to get right (at all).&lt;/P&gt;&lt;P&gt;a. Use an UF. But you said you don't want a UF and you might not get a sufficiently old UF which would still be compatible with modern Splunk receiving environment (the oldest UFs I worked with were 6.6 and they might have had no support for such old windows already; I doubt you can even get older forwarders, let alone making them work with Splunk 9+).&lt;/P&gt;&lt;P&gt;b. Query your windows from remote machine with UF by WMI&amp;nbsp; - that might again be very tricky (if possible at all) with such old Windows. And for this you'd need your machines to be domain-joined.&lt;/P&gt;&lt;P&gt;c. Use Windows Event Forwarding. Well, this actually is not available for you as I believe this feature was introduced later - 2003 server/Vista.&lt;/P&gt;&lt;P&gt;d. Use any third-party tool to dump the event log and write it to a text file or send via syslog. This is the worst possible method of ingesting windows logs. Even if you ingest the data this way it will be in a completely unusual format and you'll need to put in huge amount of time to make it readable/parseable and so on.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 07:45:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Legacy-windows-XP-Server-2000-log-onboarding-to-Splunk-without/m-p/754075#M119699</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-10-08T07:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy windows (XP, Server 2000) log onboarding to Splunk (without UF)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Legacy-windows-XP-Server-2000-log-onboarding-to-Splunk-without/m-p/754076#M119700</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/269634"&gt;@Anit_Mathew&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I don't know if it's permitted in you infrastructure, but you could try to use WMI &lt;A href="https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.1/get-windows-data/monitor-data-through-windows-management-instrumentation-wmi" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.1/get-windows-data/monitor-data-through-windows-management-instrumentation-wmi&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I usually avoid to use WMI but in this case, maybe is the easiest solution.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 07:45:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Legacy-windows-XP-Server-2000-log-onboarding-to-Splunk-without/m-p/754076#M119700</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-10-08T07:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy windows (XP, Server 2000) log onboarding to Splunk (without UF)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Legacy-windows-XP-Server-2000-log-onboarding-to-Splunk-without/m-p/754077#M119701</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/269634"&gt;@Anit_Mathew&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;My suggestion is You can deploy the Snare agent on the legacy Windows hosts (e.g., Windows XP/Server 2000) to forward Event Logs to a centralized syslog server. On that syslog server, run a Splunk Universal Forwarder (UF) to monitor the syslog files and securely forward them to Splunk for indexing and analysis.&lt;/P&gt;&lt;P&gt;Flow: Snare (legacy windows host) → Syslog server (file storage/rotation) Splunk UF → Splunk indexers.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 07:47:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Legacy-windows-XP-Server-2000-log-onboarding-to-Splunk-without/m-p/754077#M119701</guid>
      <dc:creator>thahir</dc:creator>
      <dc:date>2025-10-08T07:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy windows (XP, Server 2000) log onboarding to Splunk (without UF)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Legacy-windows-XP-Server-2000-log-onboarding-to-Splunk-without/m-p/754078#M119702</link>
      <description>&lt;P&gt;One old answers where is instructions how to read Windows evtx exports in linux.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Ingesting-offline-Windows-Event-logs-from-different-systems/m-p/649515" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Ingesting-offline-Windows-Event-logs-from-different-systems/m-p/649515&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 07:49:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Legacy-windows-XP-Server-2000-log-onboarding-to-Splunk-without/m-p/754078#M119702</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-10-08T07:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy windows (XP, Server 2000) log onboarding to Splunk (without UF)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Legacy-windows-XP-Server-2000-log-onboarding-to-Splunk-without/m-p/754089#M119704</link>
      <description>&lt;P&gt;Yes, but I'm not sure if it will work with EVT files (not EVTX!)&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 12:43:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Legacy-windows-XP-Server-2000-log-onboarding-to-Splunk-without/m-p/754089#M119704</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-10-08T12:43:53Z</dc:date>
    </item>
  </channel>
</rss>

