<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Are there limitations for a Splunk Indexer on Linux indexing imported Windows Event Logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Are-there-limitations-for-a-Splunk-Indexer-on-Linux-indexing/m-p/303641#M57328</link>
    <description>&lt;P&gt;I referenced a prior question on this regarding Linux Splunk server and Windows Event Logs: &lt;A href="https://answers.splunk.com/answers/60343/linux-splunk-server-and-windows-event-logs.html"&gt;https://answers.splunk.com/answers/60343/linux-splunk-server-and-windows-event-logs.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;But this is more than 4 years old and I am hoping there might be a new app out there.  &lt;/P&gt;

&lt;P&gt;In addition to native network monitoring through forwarders, we expect to receive Windows event logs in the native format (.evtx) on DVD.  My indexer is on a Centos box.  Do I still have to go through the "wevtutil" command to convert to XML, or is there a Splunk app that will allow me to ingest those native event logs directly?&lt;/P&gt;</description>
    <pubDate>Tue, 14 Feb 2017 20:30:57 GMT</pubDate>
    <dc:creator>thomas_porter</dc:creator>
    <dc:date>2017-02-14T20:30:57Z</dc:date>
    <item>
      <title>Are there limitations for a Splunk Indexer on Linux indexing imported Windows Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-there-limitations-for-a-Splunk-Indexer-on-Linux-indexing/m-p/303641#M57328</link>
      <description>&lt;P&gt;I referenced a prior question on this regarding Linux Splunk server and Windows Event Logs: &lt;A href="https://answers.splunk.com/answers/60343/linux-splunk-server-and-windows-event-logs.html"&gt;https://answers.splunk.com/answers/60343/linux-splunk-server-and-windows-event-logs.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;But this is more than 4 years old and I am hoping there might be a new app out there.  &lt;/P&gt;

&lt;P&gt;In addition to native network monitoring through forwarders, we expect to receive Windows event logs in the native format (.evtx) on DVD.  My indexer is on a Centos box.  Do I still have to go through the "wevtutil" command to convert to XML, or is there a Splunk app that will allow me to ingest those native event logs directly?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 20:30:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-there-limitations-for-a-Splunk-Indexer-on-Linux-indexing/m-p/303641#M57328</guid>
      <dc:creator>thomas_porter</dc:creator>
      <dc:date>2017-02-14T20:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: Are there limitations for a Splunk Indexer on Linux indexing imported Windows Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-there-limitations-for-a-Splunk-Indexer-on-Linux-indexing/m-p/303642#M57329</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;

&lt;P&gt;No that was an old threat i just finished a project using this environment and everything is good, as a charm. So dont worry, all you will need is Splunk universal forwarders on windows machines.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Melvin Gonzalez&lt;/STRONG&gt;&lt;BR /&gt;
Security Consultant&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2017 20:31:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-there-limitations-for-a-Splunk-Indexer-on-Linux-indexing/m-p/303642#M57329</guid>
      <dc:creator>mgnzlz</dc:creator>
      <dc:date>2017-03-16T20:31:18Z</dc:date>
    </item>
  </channel>
</rss>

