<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WindowsUpdateLog in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/WindowsUpdateLog/m-p/98660#M20632</link>
    <description>&lt;P&gt;Found the problem.&lt;BR /&gt;
The fields objects (transform and report) where by default configured in App context only so did not work on the Search app.&lt;BR /&gt;
Changing the relevant objects to Global makes it work as expected.&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jul 2013 08:47:07 GMT</pubDate>
    <dc:creator>yuvalba</dc:creator>
    <dc:date>2013-07-23T08:47:07Z</dc:date>
    <item>
      <title>WindowsUpdateLog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WindowsUpdateLog/m-p/98659#M20631</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I have Splunk for Windows installed and want to check the WindowsUpdate log.&lt;BR /&gt;
I am receiving the log correctly and have setup sourcetype to be WindowsUpdateLog as needed.&lt;BR /&gt;
However I don't have any fields extracted.&lt;BR /&gt;
I tested by applying the transform pid-tid-component_for_windowsupdatelog manually as:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;rex "^\S+\s+\S+\s+(?&amp;lt;pid&amp;gt;\S+)\s+(?&amp;lt;tid&amp;gt;\S+)\s+(?&amp;lt;component&amp;gt;\S+)"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And the fields are extracted correctly.&lt;BR /&gt;
Why aren't they being extracted on regular search? I must be missing something...&lt;BR /&gt;
Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:22:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WindowsUpdateLog/m-p/98659#M20631</guid>
      <dc:creator>yuvalba</dc:creator>
      <dc:date>2020-09-28T14:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: WindowsUpdateLog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WindowsUpdateLog/m-p/98660#M20632</link>
      <description>&lt;P&gt;Found the problem.&lt;BR /&gt;
The fields objects (transform and report) where by default configured in App context only so did not work on the Search app.&lt;BR /&gt;
Changing the relevant objects to Global makes it work as expected.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2013 08:47:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WindowsUpdateLog/m-p/98660#M20632</guid>
      <dc:creator>yuvalba</dc:creator>
      <dc:date>2013-07-23T08:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: WindowsUpdateLog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WindowsUpdateLog/m-p/98661#M20633</link>
      <description>&lt;P&gt;Why can't I edit my post?&lt;BR /&gt;
Whem I try to edit the title and save, it say "This field is required" under "update summary" although I fill it up.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2013 08:50:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WindowsUpdateLog/m-p/98661#M20633</guid>
      <dc:creator>yuvalba</dc:creator>
      <dc:date>2013-07-23T08:50:37Z</dc:date>
    </item>
  </channel>
</rss>

