<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WinEventLog System in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-System/m-p/370234#M67183</link>
    <description>&lt;P&gt;update: im searching Last 30 days and its only logging today if that helps. 2004 event happened 10 days ago so i am not sure if the problem is that splunk is only logging todays events or if it can see any other events&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jun 2017 16:04:48 GMT</pubDate>
    <dc:creator>santiagn</dc:creator>
    <dc:date>2017-06-23T16:04:48Z</dc:date>
    <item>
      <title>WinEventLog System</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-System/m-p/370233#M67182</link>
      <description>&lt;P&gt;hi question regarding the wineventlog system collection.&lt;/P&gt;

&lt;P&gt;for some reason splunk is only displaying event code 7036. i have a 2004 code that i am trying to log and set an alert but it is not picking it up for some reason. i see that 7036 is an information type and 2004 is a warning. what can i do to get 2004 to log?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 15:55:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-System/m-p/370233#M67182</guid>
      <dc:creator>santiagn</dc:creator>
      <dc:date>2017-06-23T15:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog System</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-System/m-p/370234#M67183</link>
      <description>&lt;P&gt;update: im searching Last 30 days and its only logging today if that helps. 2004 event happened 10 days ago so i am not sure if the problem is that splunk is only logging todays events or if it can see any other events&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 16:04:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-System/m-p/370234#M67183</guid>
      <dc:creator>santiagn</dc:creator>
      <dc:date>2017-06-23T16:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog System</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-System/m-p/370235#M67184</link>
      <description>&lt;P&gt;please share your inputs stanza for winevenlog system &lt;BR /&gt;
supposed to be something like that:&lt;BR /&gt;
    [WinEventLog://System]&lt;BR /&gt;
    disabled = 0&lt;BR /&gt;
    start_from = oldest&lt;BR /&gt;
    current_only = 0&lt;BR /&gt;
    checkpointInterval = 5&lt;BR /&gt;
    index = wineventlog&lt;BR /&gt;
    renderXml=false&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:34:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-System/m-p/370235#M67184</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2020-09-29T14:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog System</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-System/m-p/370236#M67185</link>
      <description>&lt;P&gt;i only had disabled = 0 and my index, updated to what you mentioned and still no luck, only showing todays logs.&lt;/P&gt;

&lt;P&gt;[WinEventLog://System]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
index=main&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
renderXml=false&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:38:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-System/m-p/370236#M67185</guid>
      <dc:creator>santiagn</dc:creator>
      <dc:date>2020-09-29T14:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog System</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-System/m-p/370237#M67186</link>
      <description>&lt;P&gt;figured it out,&lt;/P&gt;

&lt;P&gt;changed start_from from oldest to newest&lt;/P&gt;

&lt;P&gt;and current_only from 0 to 1&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 17:08:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-System/m-p/370237#M67186</guid>
      <dc:creator>santiagn</dc:creator>
      <dc:date>2017-06-23T17:08:55Z</dc:date>
    </item>
  </channel>
</rss>

