<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows custom events logs not showing up in Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-custom-events-logs-not-showing-up-in-Splunk/m-p/223943#M43838</link>
    <description>&lt;P&gt;Hi, as per the screenshot the path looks correct to me.&lt;BR /&gt;
Hopefully that should be working just fine.&lt;/P&gt;

&lt;P&gt;If you are happy with the resolution of this issue please do not forget to mark it as answered so that it can be closed.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
J&lt;/P&gt;</description>
    <pubDate>Fri, 30 Sep 2016 09:11:52 GMT</pubDate>
    <dc:creator>javiergn</dc:creator>
    <dc:date>2016-09-30T09:11:52Z</dc:date>
    <item>
      <title>Windows custom events logs not showing up in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-custom-events-logs-not-showing-up-in-Splunk/m-p/223938#M43833</link>
      <description>&lt;P&gt;Hi ,&lt;BR /&gt;
Below is custom event logs which I am configuring on windows forwarder but they are not showing up in Splunk. We can see events coming from default events like system,security etc. Below is syntax I am using&lt;/P&gt;

&lt;P&gt;[WinEventLog://Citirix Delivery Services]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 1&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
index = wineventlog&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/162188-picture1.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Attached screenshot shows location of event logs&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:13:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-custom-events-logs-not-showing-up-in-Splunk/m-p/223938#M43833</guid>
      <dc:creator>yanivdutt</dc:creator>
      <dc:date>2020-09-29T11:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: Windows custom events logs not showing up in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-custom-events-logs-not-showing-up-in-Splunk/m-p/223939#M43834</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Just some comments to that:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Isn't the name in your config file wrong? Shouldn't it be "Citrix Delivery Services" instead of "Citirix Delivery Services]" (notice the extra i)&lt;/LI&gt;
&lt;LI&gt;I can't see your screenshot very well but there seems to be two blank spaces between Delivery and Services, is that the case?&lt;/LI&gt;
&lt;LI&gt;Also, is "Citrix Delivery Services" the full path of your event log?&lt;/LI&gt;
&lt;LI&gt;Finally, have you tried reading from any other log in the same folder such as "Internet Explorer" and see if that works?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
J&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2016 08:23:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-custom-events-logs-not-showing-up-in-Splunk/m-p/223939#M43834</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2016-09-28T08:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Windows custom events logs not showing up in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-custom-events-logs-not-showing-up-in-Splunk/m-p/223940#M43835</link>
      <description>&lt;P&gt;Thanks for replying. It was typo in post. Was using correct syntax in my use case&lt;/P&gt;

&lt;P&gt;[WinEventLog://Citrix Delivery Services]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 1&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
index = wineventlog&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:10:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-custom-events-logs-not-showing-up-in-Splunk/m-p/223940#M43835</guid>
      <dc:creator>yanivdutt</dc:creator>
      <dc:date>2020-09-29T11:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Windows custom events logs not showing up in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-custom-events-logs-not-showing-up-in-Splunk/m-p/223941#M43836</link>
      <description>&lt;P&gt;What about the other 3 points I mentioned above?&lt;BR /&gt;
Did you manage to try any of that?&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
J&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2016 08:49:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-custom-events-logs-not-showing-up-in-Splunk/m-p/223941#M43836</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2016-09-28T08:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: Windows custom events logs not showing up in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-custom-events-logs-not-showing-up-in-Splunk/m-p/223942#M43837</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/113132"&gt;@javiergn&lt;/a&gt; &lt;BR /&gt;
Yes Citrix delivery services is complete folder. Somehow i started seeing data after windows server reboot. Now I am adding couple more customized . Below is events I want to see and screenshot. Is path mentioned correct ? This event is underneath other events from events view, but exist in same folder structure&lt;/P&gt;

&lt;P&gt;[WinEventLog://Citrix-CDF_ErrorReporter/Admin]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 1&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
index = wineventlog&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/162191-picture1.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:11:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-custom-events-logs-not-showing-up-in-Splunk/m-p/223942#M43837</guid>
      <dc:creator>yanivdutt</dc:creator>
      <dc:date>2020-09-29T11:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: Windows custom events logs not showing up in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-custom-events-logs-not-showing-up-in-Splunk/m-p/223943#M43838</link>
      <description>&lt;P&gt;Hi, as per the screenshot the path looks correct to me.&lt;BR /&gt;
Hopefully that should be working just fine.&lt;/P&gt;

&lt;P&gt;If you are happy with the resolution of this issue please do not forget to mark it as answered so that it can be closed.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
J&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2016 09:11:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-custom-events-logs-not-showing-up-in-Splunk/m-p/223943#M43838</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2016-09-30T09:11:52Z</dc:date>
    </item>
  </channel>
</rss>

