<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to ingest multiple window event log .evtx files in zip format in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-ingest-multiple-window-event-log-evtx-files-in-zip/m-p/349476#M64155</link>
    <description>&lt;P&gt;We find it's a bug in v6.6.0. It targets to have fix in v6.6.4. &lt;/P&gt;</description>
    <pubDate>Thu, 03 Aug 2017 04:33:10 GMT</pubDate>
    <dc:creator>tlam_splunk</dc:creator>
    <dc:date>2017-08-03T04:33:10Z</dc:date>
    <item>
      <title>Unable to ingest multiple window event log .evtx files in zip format</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-ingest-multiple-window-event-log-evtx-files-in-zip/m-p/349475#M64154</link>
      <description>&lt;P&gt;We're using v6.6.0. It's working fine to ingest single zip file of window event log. But we got the problem to ingest multiple zip files of evtx files. The data could be go into Splunk but they have incorrect sourcetype. The sourcetype is random, maybe the name of event log or zip path. Also, the message field inside the event has missing data. Is there any ideas ?  &lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 04:31:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-ingest-multiple-window-event-log-evtx-files-in-zip/m-p/349475#M64154</guid>
      <dc:creator>tlam_splunk</dc:creator>
      <dc:date>2017-08-03T04:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to ingest multiple window event log .evtx files in zip format</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-ingest-multiple-window-event-log-evtx-files-in-zip/m-p/349476#M64155</link>
      <description>&lt;P&gt;We find it's a bug in v6.6.0. It targets to have fix in v6.6.4. &lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 04:33:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-ingest-multiple-window-event-log-evtx-files-in-zip/m-p/349476#M64155</guid>
      <dc:creator>tlam_splunk</dc:creator>
      <dc:date>2017-08-03T04:33:10Z</dc:date>
    </item>
  </channel>
</rss>

