<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Metadata for Windows EVTX Files in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Metadata-for-Windows-EVTX-Files/m-p/74614#M15244</link>
    <description>&lt;P&gt;That's a good point.  I will send this to the docs team and them updated.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 21 Oct 2010 23:07:32 GMT</pubDate>
    <dc:creator>Ledio_Ago</dc:creator>
    <dc:date>2010-10-21T23:07:32Z</dc:date>
    <item>
      <title>Splunk Metadata for Windows EVTX Files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Metadata-for-Windows-EVTX-Files/m-p/74611#M15241</link>
      <description>&lt;P&gt;I am at a site where we are using a Splunk Forwarder to mount a DFS share and read EVTX Archive Files placed there by another entity.&lt;/P&gt;

&lt;P&gt;The Splunk Forwarder is 4.1.5 x64 on Windows 2008.
The Splunk Forwarder is also a Search Head federating search requests to the same indexer where it is sending these evtx logs (not that it should make a difference).&lt;/P&gt;

&lt;P&gt;There are no problems with the reads/parse of the EVTX files; however, we appear to have a problem with modifying the Splunk Metadata for these events.&lt;/P&gt;

&lt;P&gt;Ideally, we would customize the &lt;I&gt;Index&lt;/I&gt; field.  This appears to not work.&lt;/P&gt;

&lt;P&gt;In the &lt;I&gt;inputs.conf&lt;/I&gt; I have tried setting the &lt;I&gt;index&lt;/I&gt; and the &lt;I&gt;sourcetype&lt;/I&gt; but no matter what I enter, here is where the events show up:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;index=main&lt;/LI&gt;
&lt;LI&gt;sourcetype=WinEventLog:Security&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I have also tried using props/transforms to set the Metatdata DEST_KEY on both the Forwarder and the Indexer (several ways).  No matter, what I select or set, it appears that I can have no impact on the &lt;I&gt;index&lt;/I&gt; or &lt;I&gt;sourcetype&lt;/I&gt;.&lt;/P&gt;

&lt;P&gt;My thought is that since the evtx files are binary, that a separate process handles these that isn't accepting modification.&lt;/P&gt;

&lt;P&gt;Is this crazy or some limitation of the (evt|evtx) parser?&lt;/P&gt;

&lt;P&gt;Sean&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2010 07:05:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Metadata-for-Windows-EVTX-Files/m-p/74611#M15241</guid>
      <dc:creator>sdwilkerson</dc:creator>
      <dc:date>2010-10-21T07:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Metadata for Windows EVTX Files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Metadata-for-Windows-EVTX-Files/m-p/74612#M15242</link>
      <description>&lt;P&gt;Sean, that is true.  You can't set index, source or any other metadata for ".evt(x)" type inputs.  There is a special process that does the parsing, instead of the tailing processor, and it doesn't support setting those type of metadata.&lt;/P&gt;

&lt;P&gt;This has been fixed and will be shipped with next major version of Splunk, 4.2&lt;/P&gt;

&lt;P&gt;Thanks, 
Ledio &lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2010 08:07:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Metadata-for-Windows-EVTX-Files/m-p/74612#M15242</guid>
      <dc:creator>Ledio_Ago</dc:creator>
      <dc:date>2010-10-21T08:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Metadata for Windows EVTX Files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Metadata-for-Windows-EVTX-Files/m-p/74613#M15243</link>
      <description>&lt;P&gt;Ledio,&lt;BR /&gt;
Much appreciated.  I thought I was going nuts. Wish the docs had warned me.&lt;BR /&gt;
Sean&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2010 08:20:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Metadata-for-Windows-EVTX-Files/m-p/74613#M15243</guid>
      <dc:creator>sdwilkerson</dc:creator>
      <dc:date>2010-10-21T08:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Metadata for Windows EVTX Files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Metadata-for-Windows-EVTX-Files/m-p/74614#M15244</link>
      <description>&lt;P&gt;That's a good point.  I will send this to the docs team and them updated.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2010 23:07:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Metadata-for-Windows-EVTX-Files/m-p/74614#M15244</guid>
      <dc:creator>Ledio_Ago</dc:creator>
      <dc:date>2010-10-21T23:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Metadata for Windows EVTX Files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Metadata-for-Windows-EVTX-Files/m-p/74615#M15245</link>
      <description>&lt;P&gt;Done. (from the docs team)&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2010 02:51:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Metadata-for-Windows-EVTX-Files/m-p/74615#M15245</guid>
      <dc:creator>malmoore</dc:creator>
      <dc:date>2010-10-22T02:51:25Z</dc:date>
    </item>
  </channel>
</rss>

