<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Splunk index Windows Event Log(evt,evtx) files? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9290#M39</link>
    <description>&lt;P&gt;Well, they aren't text files at all, so the indexing is a bit different than a log file.  &lt;/P&gt;

&lt;P&gt;It's sensitive to running on windows, and for best results you want to index them on the host which produced them (for example to expand usernames and the like).  For reasonable results the dlls which were involved in creating the events should be availble, which typically means indexing Vista-generated events on Vista, and so on.&lt;/P&gt;

&lt;P&gt;The configuration necessary to index them &lt;EM&gt;should&lt;/EM&gt; be just like a traditional text log, simply point a monitor input at the file.  I haven't checked how the files are recognized -- by name, by content, or otherwise.  Does anyone know?&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jan 2010 12:09:22 GMT</pubDate>
    <dc:creator>jrodman</dc:creator>
    <dc:date>2010-01-20T12:09:22Z</dc:date>
    <item>
      <title>Can Splunk index Windows Event Log(evt,evtx) files?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9288#M37</link>
      <description>&lt;P&gt;Windows Server 2003, Windows XP and 2000 generate evt files, where Windows Vista, 2008 Server, Windows 7 generate evtx files.  Can Splunk index these files just like any other text file?&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jan 2010 16:39:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9288#M37</guid>
      <dc:creator>Ledio_Ago</dc:creator>
      <dc:date>2010-01-16T16:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk index Windows Event Log(evt,evtx) files?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9289#M38</link>
      <description>&lt;P&gt;Yes, a Splunk 4 instance running on Windows can index those files. Just add a file monitoring data input and Splunk will decode the event log content. It doesn't work on *nix as far as I know, though.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jan 2010 18:45:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9289#M38</guid>
      <dc:creator>ziegfried</dc:creator>
      <dc:date>2010-01-17T18:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk index Windows Event Log(evt,evtx) files?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9290#M39</link>
      <description>&lt;P&gt;Well, they aren't text files at all, so the indexing is a bit different than a log file.  &lt;/P&gt;

&lt;P&gt;It's sensitive to running on windows, and for best results you want to index them on the host which produced them (for example to expand usernames and the like).  For reasonable results the dlls which were involved in creating the events should be availble, which typically means indexing Vista-generated events on Vista, and so on.&lt;/P&gt;

&lt;P&gt;The configuration necessary to index them &lt;EM&gt;should&lt;/EM&gt; be just like a traditional text log, simply point a monitor input at the file.  I haven't checked how the files are recognized -- by name, by content, or otherwise.  Does anyone know?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2010 12:09:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9290#M39</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2010-01-20T12:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk index Windows Event Log(evt,evtx) files?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9291#M40</link>
      <description>&lt;P&gt;Yes. The documentation on how to do this exists here: &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/MonitorWindowsdata" rel="nofollow"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Data/MonitorWindowsdata&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In short, you can add these files as inputs, but be sure that these files are not being written to while splunk reads it. Also, unlike other log files, using the upload function will not work with these files. Splunk will recognize the file by the file extension .evt or .evtx. Since Splunk utilizes native Windows APIs to extract information from these files, you need to run Splunk on windows.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2010 06:58:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9291#M40</guid>
      <dc:creator>bchen</dc:creator>
      <dc:date>2010-01-21T06:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk index Windows Event Log(evt,evtx) files?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9292#M41</link>
      <description>&lt;P&gt;We've had several problems with this issue. Actually the Splunk docs is a bit misleading on this. The only guaranteed method to index Windows Event Logs events is to define a native input on a Splunk instance -could be a (light)forwarder too- on the same windows machine that generate the Events to index (add for instance a [WinEventLog:Application] stanza in inputs.conf).&lt;/P&gt;

&lt;P&gt;As you can see from the last updated docs (http://www.splunk.com/base/Documentation/4.1.1/Admin/MonitorWindowsdata), indexing exported evt data has several limitations, due to the Microsoft proprietary way to generate those .evt files, which embed links to the DLLs used to generate them.&lt;/P&gt;

&lt;P&gt;So take care when planning a Splunk deployment were there will be several evt files (or data) to index!&lt;/P&gt;

&lt;P&gt;Marco Scala&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2010 19:05:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9292#M41</guid>
      <dc:creator>marcoscala</dc:creator>
      <dc:date>2010-04-27T19:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk index Windows Event Log(evt,evtx) files?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9293#M42</link>
      <description>&lt;P&gt;Splunk 1.4.1 x64 win32. Splunk can't index evt/evtx files due to binary...why???&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2010 18:56:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9293#M42</guid>
      <dc:creator>nvoitov</dc:creator>
      <dc:date>2010-08-23T18:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk index Windows Event Log(evt,evtx) files?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9294#M43</link>
      <description>&lt;P&gt;Please edit and clarify what version of Splunk you're talking about. Better yet, it sounds to me like you have a new question, so you should probably post new, rather than an answer to this one.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2010 22:17:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9294#M43</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-08-23T22:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk index Windows Event Log(evt,evtx) files?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9295#M44</link>
      <description>&lt;P&gt;the posted link is broken.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2011 20:46:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9295#M44</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2011-06-09T20:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk index Windows Event Log(evt,evtx) files?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9296#M45</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/MonitorWindowsdata"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Data/MonitorWindowsdata&lt;/A&gt; is the latest doco.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Jul 2012 15:28:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9296#M45</guid>
      <dc:creator>rturk</dc:creator>
      <dc:date>2012-07-15T15:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk index Windows Event Log(evt,evtx) files?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9297#M46</link>
      <description>&lt;P&gt;Updated both docs URLs to permanent links&lt;/P&gt;</description>
      <pubDate>Fri, 21 Dec 2012 22:59:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9297#M46</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2012-12-21T22:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk index Windows Event Log(evt,evtx) files?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9298#M47</link>
      <description>&lt;P&gt;the link fricking doesn't work!!!! &lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2019 12:08:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-index-Windows-Event-Log-evt-evtx-files/m-p/9298#M47</guid>
      <dc:creator>rmarietan</dc:creator>
      <dc:date>2019-11-29T12:08:24Z</dc:date>
    </item>
  </channel>
</rss>

