<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I upload an Administrative Events.evtx file? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359605#M65614</link>
    <description>&lt;P&gt;Hi @ddrillic, Following up on my previous answer after more research. @ppablo and @aaraneta helped me look through several other related inquiries and the documentation on Splunk Docs, and unfortunately it looks like the original evtx files can't be uploaded in this way as you requested due to the proprietary nature of the evtx files. You can read more from the answers to these questions here: &lt;A href="https://answers.splunk.com/topics/evtx.html"&gt;https://answers.splunk.com/topics/evtx.html&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;We have a pretty active public Slack chat if you'd like to reach out there for more info or to see if an active user has found a workaround. You first have to request access through &lt;A href="http://splk.it/slack"&gt;http://splk.it/slack&lt;/A&gt;. Fill out the form, and once you receive the approval email from our Community Manager (usually the approval process may take a couple days), you can access Slack.com and ask for help in the #general channel.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Aug 2017 23:01:22 GMT</pubDate>
    <dc:creator>lfedak_splunk</dc:creator>
    <dc:date>2017-08-08T23:01:22Z</dc:date>
    <item>
      <title>How can I upload an Administrative Events.evtx file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359601#M65610</link>
      <description>&lt;P&gt;We are trying to upload the Administrative Events.evtx file via the Add Data interface. However, the interface doesn't seem to provide the option to treat the file as a Windows events log file.&lt;/P&gt;

&lt;P&gt;We see - &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3339i7520DA6C4BBE16C1/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 21:29:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359601#M65610</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-08-08T21:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: How can I upload an Administrative Events.evtx file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359602#M65611</link>
      <description>&lt;P&gt;Hey @ddrillic, Here's some documentation on adding this type of file. &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/MonitorWindowsdata"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Data/MonitorWindowsdata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 21:54:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359602#M65611</guid>
      <dc:creator>lfedak_splunk</dc:creator>
      <dc:date>2017-08-08T21:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: How can I upload an Administrative Events.evtx file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359603#M65612</link>
      <description>&lt;P&gt;Great, but I would like to &lt;STRONG&gt;upload&lt;/STRONG&gt; them as files and not monitor them, which we can't at this point...&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 21:56:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359603#M65612</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-08-08T21:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: How can I upload an Administrative Events.evtx file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359604#M65613</link>
      <description>&lt;P&gt;Here are a few Answers links as well: &lt;BR /&gt;
Through the interface: &lt;A href="https://answers.splunk.com/answers/528735/how-to-index-exported-evt-and-evtx-files.html"&gt;https://answers.splunk.com/answers/528735/how-to-index-exported-evt-and-evtx-files.html&lt;/A&gt;&lt;BR /&gt;
Using a forwarder or using a work-around to change them into csv or text files: &lt;A href="https://answers.splunk.com/answers/479464/how-to-index-evtx-files-in-splunk.html"&gt;https://answers.splunk.com/answers/479464/how-to-index-evtx-files-in-splunk.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 21:57:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359604#M65613</guid>
      <dc:creator>lfedak_splunk</dc:creator>
      <dc:date>2017-08-08T21:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: How can I upload an Administrative Events.evtx file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359605#M65614</link>
      <description>&lt;P&gt;Hi @ddrillic, Following up on my previous answer after more research. @ppablo and @aaraneta helped me look through several other related inquiries and the documentation on Splunk Docs, and unfortunately it looks like the original evtx files can't be uploaded in this way as you requested due to the proprietary nature of the evtx files. You can read more from the answers to these questions here: &lt;A href="https://answers.splunk.com/topics/evtx.html"&gt;https://answers.splunk.com/topics/evtx.html&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;We have a pretty active public Slack chat if you'd like to reach out there for more info or to see if an active user has found a workaround. You first have to request access through &lt;A href="http://splk.it/slack"&gt;http://splk.it/slack&lt;/A&gt;. Fill out the form, and once you receive the approval email from our Community Manager (usually the approval process may take a couple days), you can access Slack.com and ask for help in the #general channel.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 23:01:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359605#M65614</guid>
      <dc:creator>lfedak_splunk</dc:creator>
      <dc:date>2017-08-08T23:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: How can I upload an Administrative Events.evtx file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359606#M65615</link>
      <description>&lt;P&gt;Decoding of &lt;CODE&gt;evtx&lt;/CODE&gt; files must be done in context of the Windows server where it was generated and upload does not work.  For a great explanation, see the answer by @inventsekar here (be sure to UpVote him):&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/479464/how-to-index-evtx-files-in-splunk.html"&gt;https://answers.splunk.com/answers/479464/how-to-index-evtx-files-in-splunk.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 11:57:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359606#M65615</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-08-09T11:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: How can I upload an Administrative Events.evtx file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359607#M65616</link>
      <description>&lt;P&gt;Very kind @woodcock &lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2017 00:37:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359607#M65616</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-08-13T00:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: How can I upload an Administrative Events.evtx file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359608#M65617</link>
      <description>&lt;P&gt;Just ran into this same issue, having trouble ingesting these .evtx logs (from Citrix application server). Also read thru the link woodcock provided (&lt;A href="https://answers.splunk.com/answers/479464/how-to-index-evtx-files-in-splunk.html"&gt;https://answers.splunk.com/answers/479464/how-to-index-evtx-files-in-splunk.html&lt;/A&gt;) and didn't see any clear answer.&lt;/P&gt;

&lt;P&gt;Using a forwarder to monitor the file, also used the sourcetype=WinEventLog, after installing the Windows TA...but getting the same results as ddrillic. &lt;/P&gt;

&lt;P&gt;Anyone got more info on how to ingest these logs? Thanks!&lt;/P&gt;

&lt;P&gt;Joe&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2019 16:41:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359608#M65617</guid>
      <dc:creator>joesrepsolc</dc:creator>
      <dc:date>2019-12-13T16:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: How can I upload an Administrative Events.evtx file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359609#M65618</link>
      <description>&lt;P&gt;I believe that @landen99 @alanden_splunk can shed some light on this.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2019 17:03:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359609#M65618</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-12-13T17:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: How can I upload an Administrative Events.evtx file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359610#M65619</link>
      <description>&lt;P&gt;@joesrepsolc The solution appears fairly complicated, so clarity is not going to be expected when using Splunk to do it.  I actually prefer the other answer by @tnesavich for the sake of clarity.  But I expect it is much simpler to use the python method, not mentioned in those answers.  Have you looked at python-evtx? &lt;A href="https://github.com/williballenthin/python-evtx"&gt;https://github.com/williballenthin/python-evtx&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Dec 2019 15:22:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-upload-an-Administrative-Events-evtx-file/m-p/359610#M65619</guid>
      <dc:creator>landen99</dc:creator>
      <dc:date>2019-12-14T15:22:34Z</dc:date>
    </item>
  </channel>
</rss>

