<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I index Kaspersky Security Center logs in Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-Kaspersky-Security-Center-logs-in-Splunk/m-p/181146#M36337</link>
    <description>&lt;P&gt;A few more questions/comments to help pinpoint where things are going wrong:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Is it a local user or domain user?

&lt;UL&gt;
&lt;LI&gt; Does the service start fine when you manually try it after a reboot?&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;LI&gt;Set it to autostart(delayed) instead of just autostart and see if it works then.&lt;/LI&gt;
&lt;LI&gt;Try is to set it temporarily to use the local SYSTEM login and see if that works.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Note that if you set it to autostart(delayed) it can take several minutes to actually start, so don't be in a hurry.&lt;/P&gt;

&lt;P&gt;after You can start by reading &lt;STRONG&gt;splunkd.log&lt;/STRONG&gt; files on your forwarders, it's can be found at &lt;STRONG&gt;$SPLUNK_HOME$/var/log/splunk&lt;/STRONG&gt; folder. This log use be very helpful.&lt;/P&gt;

&lt;P&gt;I figured it out. The solution is to add a section and stanza in the inputs.conf file on UF-end.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  [WinEventLogs: Kaspersky Event Logs]
     disabled = 0
     start_from = oldest
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then, restart the SplunkForwarder Service.&lt;/P&gt;</description>
    <pubDate>Sat, 27 Jun 2015 10:10:12 GMT</pubDate>
    <dc:creator>fdi01</dc:creator>
    <dc:date>2015-06-27T10:10:12Z</dc:date>
    <item>
      <title>How do I index Kaspersky Security Center logs in Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-Kaspersky-Security-Center-logs-in-Splunk/m-p/181145#M36336</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'd like to monitor the logs of Kaspersky Security Center with Splunk . I found that I should add in inputs.conf on the forwarders :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog://Kaspersky Event Log]
disabled = 0
start_from = oldest
current_only = 0
checkpointInterval = 5
index = kaspersky
renderXml = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I do this and I restart the service of the forwarder, but after doing this, the forwarder is stopped !!&lt;/P&gt;

&lt;P&gt;Any one can help me to monitor the logs of Kaspersky?&lt;/P&gt;

&lt;P&gt;Thank you very much&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jun 2015 09:16:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-Kaspersky-Security-Center-logs-in-Splunk/m-p/181145#M36336</guid>
      <dc:creator>Rimah</dc:creator>
      <dc:date>2015-06-27T09:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: How do I index Kaspersky Security Center logs in Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-Kaspersky-Security-Center-logs-in-Splunk/m-p/181146#M36337</link>
      <description>&lt;P&gt;A few more questions/comments to help pinpoint where things are going wrong:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Is it a local user or domain user?

&lt;UL&gt;
&lt;LI&gt; Does the service start fine when you manually try it after a reboot?&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;LI&gt;Set it to autostart(delayed) instead of just autostart and see if it works then.&lt;/LI&gt;
&lt;LI&gt;Try is to set it temporarily to use the local SYSTEM login and see if that works.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Note that if you set it to autostart(delayed) it can take several minutes to actually start, so don't be in a hurry.&lt;/P&gt;

&lt;P&gt;after You can start by reading &lt;STRONG&gt;splunkd.log&lt;/STRONG&gt; files on your forwarders, it's can be found at &lt;STRONG&gt;$SPLUNK_HOME$/var/log/splunk&lt;/STRONG&gt; folder. This log use be very helpful.&lt;/P&gt;

&lt;P&gt;I figured it out. The solution is to add a section and stanza in the inputs.conf file on UF-end.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  [WinEventLogs: Kaspersky Event Logs]
     disabled = 0
     start_from = oldest
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then, restart the SplunkForwarder Service.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jun 2015 10:10:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-Kaspersky-Security-Center-logs-in-Splunk/m-p/181146#M36337</guid>
      <dc:creator>fdi01</dc:creator>
      <dc:date>2015-06-27T10:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: How do I index Kaspersky Security Center logs in Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-Kaspersky-Security-Center-logs-in-Splunk/m-p/181147#M36338</link>
      <description>&lt;P&gt;Thank you for your response you find below the responses of your questions:&lt;/P&gt;

&lt;P&gt;local user or domain user? local user&lt;BR /&gt;
Does the service start fine when you manually try it after a reboot? yes&lt;/P&gt;

&lt;P&gt;This problem come only if i add the instructyions in inputs.conf of kaspersky ? &lt;BR /&gt;
when I delete these lines splunk universal forwarder continue work fine !&lt;/P&gt;

&lt;P&gt;My be I do a mistak in the inputs .conf for kaspersky &lt;BR /&gt;
[WinEventLog://Kaspersky Event Log]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
index = kaspersky&lt;BR /&gt;
renderXml = false&lt;/P&gt;

&lt;P&gt;Please correct these lines if there is a mistake or tell me how can I monitor the logs of kaspersky??&lt;BR /&gt;
The only way to index Kaspersky logs  is by adding these lines in inputs.conf??&lt;BR /&gt;
Thank you !&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:24:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-Kaspersky-Security-Center-logs-in-Splunk/m-p/181147#M36338</guid>
      <dc:creator>Rimah</dc:creator>
      <dc:date>2020-09-28T20:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: How do I index Kaspersky Security Center logs in Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-Kaspersky-Security-Center-logs-in-Splunk/m-p/181148#M36339</link>
      <description>&lt;P&gt;I figured it out. The solution is to add a section and stanza in the inputs.conf file on UF-end.&lt;/P&gt;

&lt;P&gt;[WinEventLogs: Kaspersky Event Logs]&lt;BR /&gt;
 disabled = 0&lt;BR /&gt;
 start_from = oldest&lt;/P&gt;

&lt;P&gt;Then, restart the SplunkForwarder Service.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jun 2015 19:17:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-Kaspersky-Security-Center-logs-in-Splunk/m-p/181148#M36339</guid>
      <dc:creator>fdi01</dc:creator>
      <dc:date>2015-06-27T19:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: How do I index Kaspersky Security Center logs in Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-Kaspersky-Security-Center-logs-in-Splunk/m-p/181149#M36340</link>
      <description>&lt;P&gt;Hello ; &lt;/P&gt;

&lt;P&gt;Thank you for your response , I add this lines without any result . You will find below the error message :&lt;/P&gt;

&lt;P&gt;Invalid key in stanza [WinEventLogs: Kaspersky Event Logs] in C:&lt;BR /&gt;
\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf, line 6: st&lt;BR /&gt;
art_from  (value:  oldest)&lt;/P&gt;

&lt;P&gt;Do you please have any idea on how to solve this issue&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2015 12:42:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-Kaspersky-Security-Center-logs-in-Splunk/m-p/181149#M36340</guid>
      <dc:creator>Rimah</dc:creator>
      <dc:date>2015-06-29T12:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: How do I index Kaspersky Security Center logs in Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-Kaspersky-Security-Center-logs-in-Splunk/m-p/540073#M90439</link>
      <description>&lt;P&gt;But does these mapping parse the data so that it populates in ES&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 11:03:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-Kaspersky-Security-Center-logs-in-Splunk/m-p/540073#M90439</guid>
      <dc:creator>MTD</dc:creator>
      <dc:date>2021-02-16T11:03:33Z</dc:date>
    </item>
  </channel>
</rss>

