<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Read logs from Microsoft-Windows-Windows Defender/Operational in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407662#M72279</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I am trying to read from events logs namely {Microsoft-Windows-Windows Defender/Operational}.&lt;BR /&gt;
From Manager&amp;gt;Data Inputs&amp;gt;Remote Event Log Collections, I get only the list below as logs:&lt;BR /&gt;
Application&lt;BR /&gt;
Security&lt;BR /&gt;
System&lt;BR /&gt;
Hardware Events&lt;BR /&gt;
Internet Explorer&lt;BR /&gt;
Key Management Service&lt;BR /&gt;
MSExchange Management&lt;BR /&gt;
Windows Powershell&lt;/P&gt;

&lt;P&gt;I put the following in local\inputs.conf:&lt;/P&gt;

&lt;P&gt;[WinEventLog://Microsoft-Windows-Windows Defender/Operational]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
evt_resolve_ad_obj = 1&lt;BR /&gt;
checkpointInterval = 5&lt;/P&gt;

&lt;P&gt;And it is not working. How to do so? Kinldy advise.&lt;BR /&gt;
IR&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 22:47:21 GMT</pubDate>
    <dc:creator>irshadrahimbux</dc:creator>
    <dc:date>2020-09-29T22:47:21Z</dc:date>
    <item>
      <title>Read logs from Microsoft-Windows-Windows Defender/Operational</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407662#M72279</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I am trying to read from events logs namely {Microsoft-Windows-Windows Defender/Operational}.&lt;BR /&gt;
From Manager&amp;gt;Data Inputs&amp;gt;Remote Event Log Collections, I get only the list below as logs:&lt;BR /&gt;
Application&lt;BR /&gt;
Security&lt;BR /&gt;
System&lt;BR /&gt;
Hardware Events&lt;BR /&gt;
Internet Explorer&lt;BR /&gt;
Key Management Service&lt;BR /&gt;
MSExchange Management&lt;BR /&gt;
Windows Powershell&lt;/P&gt;

&lt;P&gt;I put the following in local\inputs.conf:&lt;/P&gt;

&lt;P&gt;[WinEventLog://Microsoft-Windows-Windows Defender/Operational]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
evt_resolve_ad_obj = 1&lt;BR /&gt;
checkpointInterval = 5&lt;/P&gt;

&lt;P&gt;And it is not working. How to do so? Kinldy advise.&lt;BR /&gt;
IR&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:47:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407662#M72279</guid>
      <dc:creator>irshadrahimbux</dc:creator>
      <dc:date>2020-09-29T22:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: Read logs from Microsoft-Windows-Windows Defender/Operational</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407663#M72280</link>
      <description>&lt;P&gt;I finally got it working as follows:&lt;BR /&gt;
[WinEventLog://Microsoft-Windows-Windows Defender/Operational]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
index = default&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
checkpointInterval = 5&lt;/P&gt;

&lt;P&gt;However, it is imported as plain XML as follows:&lt;BR /&gt;
&lt;EM&gt;&lt;CODE&gt;&amp;lt;Event xmlns='&lt;A href="http://schemas.microsoft.com/win/2004/08/events/event'&amp;gt;&amp;lt;System&amp;gt;&amp;lt;Provider" target="_blank"&gt;http://schemas.microsoft.com/win/2004/08/events/event'&amp;gt;&amp;lt;System&amp;gt;&amp;lt;Provider&lt;/A&gt; Name='Microsoft-Windows-Windows Defender' Guid='{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}'/&amp;gt;&amp;lt;EventID&amp;gt;1117&amp;lt;/EventID&amp;gt;&amp;lt;Version&amp;gt;0&amp;lt;/Version&amp;gt;&amp;lt;Level&amp;gt;4&amp;lt;/Level&amp;gt;&amp;lt;Task&amp;gt;0&amp;lt;/Task&amp;gt;&amp;lt;Opcode&amp;gt;0&amp;lt;/Opcode&amp;gt;&amp;lt;Keywords&amp;gt;0x8000000000000000&amp;lt;/Keywords&amp;gt;&amp;lt;TimeCreated SystemTime='2019-01-17T07:09:58.515056300Z'/&amp;gt;&amp;lt;EventRecordID&amp;gt;5462&amp;lt;/EventRecordID&amp;gt;&amp;lt;Correlation ActivityID='{73509B89-4403-46D8-B260-204DD0098E76}'/&amp;gt;&amp;lt;Execution ProcessID='2620' ThreadID='15224'/&amp;gt;&amp;lt;Channel&amp;gt;Microsoft-Windows-Windows Defender/Operational&amp;lt;/Channel&amp;gt;&amp;lt;Computer&amp;gt;IT-IRSHAD.Emtel.Org&amp;lt;/Computer&amp;gt;&amp;lt;Security UserID='S-1-5-18'/&amp;gt;&amp;lt;/System&amp;gt;&amp;lt;EventData&amp;gt;&amp;lt;Data Name='Product Name'&amp;gt;%%827&amp;lt;/Data&amp;gt;&amp;lt;Data Name='Product Version'&amp;gt;4.8.10240.16384&amp;lt;/Data&amp;gt;&amp;lt;Data Name='Detection ID'&amp;gt;{BDDC5EF0-DF00-46E0-B606-B8696AF2C89D}&amp;lt;/Data&amp;gt;&amp;lt;Data Name='Detection Time'&amp;gt;2019-01-17T07:09:03.351Z&amp;lt;/Data&amp;gt;&amp;lt;Data Name='Unused'&amp;gt;&amp;lt;/Data&amp;gt;&amp;lt;Data Name='Unused2'&amp;gt;&amp;lt;/Data&amp;gt;&amp;lt;Data Name='Threat ID'&amp;gt;2147519003&amp;lt;/Data&amp;gt;&lt;/CODE&gt;&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Nothing has been decoded. How to get same decoded?&lt;/P&gt;

&lt;P&gt;Rgds,&lt;BR /&gt;
IR&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:47:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407663#M72280</guid>
      <dc:creator>irshadrahimbux</dc:creator>
      <dc:date>2020-09-29T22:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: Read logs from Microsoft-Windows-Windows Defender/Operational</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407664#M72281</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;did you see that there is a TA for Defender on splunkbase? Is providin inputs, so it might be helpful to you?&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3734/"&gt;https://splunkbase.splunk.com/app/3734/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 07:24:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407664#M72281</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2019-01-17T07:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: Read logs from Microsoft-Windows-Windows Defender/Operational</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407665#M72282</link>
      <description>&lt;P&gt;Are you able to see logs in Windows Event Viewer?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 07:33:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407665#M72282</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2019-01-17T07:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Read logs from Microsoft-Windows-Windows Defender/Operational</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407666#M72283</link>
      <description>&lt;P&gt;Yes, I manage to read it now. But the XML is not formatted at all.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'&amp;gt;&amp;lt;System&amp;gt;&amp;lt;Provider Name='Microsoft-Windows-Windows Defender' Guid='{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}'/&amp;gt;&amp;lt;EventID&amp;gt;1117&amp;lt;/EventID&amp;gt;&amp;lt;Version&amp;gt;0&amp;lt;/Version&amp;gt;&amp;lt;Level&amp;gt;4&amp;lt;/Level&amp;gt;&amp;lt;Task&amp;gt;0&amp;lt;/Task&amp;gt;&amp;lt;Opcode&amp;gt;0&amp;lt;/Opcode&amp;gt;&amp;lt;Keywords&amp;gt;0x8000000000000000&amp;lt;/Keywords&amp;gt;&amp;lt;TimeCreated SystemTime='2019-01-17T07:30:39.203431700Z'/&amp;gt;&amp;lt;EventRecordID&amp;gt;5464&amp;lt;/EventRecordID&amp;gt;&amp;lt;Correlation ActivityID='{836F339B-7655-4283-9C51-91811E024137}'/&amp;gt;&amp;lt;Execution ProcessID='2620' ThreadID='6184'/&amp;gt;&amp;lt;Channel&amp;gt;Microsoft-Windows-Windows Defender/Operational&amp;lt;/Channel&amp;gt;&amp;lt;Computer&amp;gt;XXX&amp;lt;/Computer&amp;gt;&amp;lt;Security UserID='S-1-5-18'/&amp;gt;&amp;lt;/System&amp;gt;&amp;lt;EventData&amp;gt;&amp;lt;Data Name='Product Name'&amp;gt;%%827&amp;lt;/Data&amp;gt;&amp;lt;Data Name='Product Version'&amp;gt;4.8.10240.16384&amp;lt;/Data&amp;gt;&amp;lt;Data Name='Detection ID'&amp;gt;{F8F2390A-DEBD-4B5E-9ADF-491B1EC25132}&amp;lt;/Data&amp;gt;&amp;lt;Data Name='Detection Time'&amp;gt;2019-01-17T07:29:43.550Z&amp;lt;/Data&amp;gt;&amp;lt;Data Name='Unused'&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Anything on how to decode same?&lt;BR /&gt;
Rgds,&lt;BR /&gt;
IR&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 07:36:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407666#M72283</guid>
      <dc:creator>irshadrahimbux</dc:creator>
      <dc:date>2019-01-17T07:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: Read logs from Microsoft-Windows-Windows Defender/Operational</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407667#M72284</link>
      <description>&lt;P&gt;yeah I got this. However, i wanted to add via the normal way and not using the TA for Defender as I willhave other logs to add in the future where no TA is available.&lt;BR /&gt;
If i got this one works, all other will follow same principle.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 07:38:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407667#M72284</guid>
      <dc:creator>irshadrahimbux</dc:creator>
      <dc:date>2019-01-17T07:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Read logs from Microsoft-Windows-Windows Defender/Operational</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407668#M72285</link>
      <description>&lt;P&gt;Just download it and have a look at it, there are field extractions for your unformatted XML as well.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 07:46:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407668#M72285</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2019-01-17T07:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: Read logs from Microsoft-Windows-Windows Defender/Operational</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407669#M72286</link>
      <description>&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/133533/xml-extraction.html?utm_source=typeahead&amp;amp;utm_medium=newquestion&amp;amp;utm_campaign=no_votes_sort_relev"&gt;https://answers.splunk.com/answers/133533/xml-extraction.html?utm_source=typeahead&amp;amp;utm_medium=newquestion&amp;amp;utm_campaign=no_votes_sort_relev&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Try this for xml field extractions&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 08:47:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407669#M72286</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2019-01-17T08:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: Read logs from Microsoft-Windows-Windows Defender/Operational</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407670#M72287</link>
      <description>&lt;P&gt;You were completely right.&lt;BR /&gt;
I have downloaded it and it simplify everything. Some tweaks had to be done in the inputs.conf&lt;BR /&gt;
But all is well and works brilliantly.&lt;/P&gt;

&lt;P&gt;Many thanks again.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 09:42:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407670#M72287</guid>
      <dc:creator>irshadrahimbux</dc:creator>
      <dc:date>2019-01-17T09:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Read logs from Microsoft-Windows-Windows Defender/Operational</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407671#M72288</link>
      <description>&lt;P&gt;Will try this too.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 09:43:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407671#M72288</guid>
      <dc:creator>irshadrahimbux</dc:creator>
      <dc:date>2019-01-17T09:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: Read logs from Microsoft-Windows-Windows Defender/Operational</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407672#M72289</link>
      <description>&lt;P&gt;I noticed it works for localhost alarms.&lt;BR /&gt;
However for remote computers, the event is not raised.&lt;/P&gt;

&lt;P&gt;Any idea what i am missing?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 09:59:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407672#M72289</guid>
      <dc:creator>irshadrahimbux</dc:creator>
      <dc:date>2019-01-17T09:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Read logs from Microsoft-Windows-Windows Defender/Operational</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407673#M72290</link>
      <description>&lt;P&gt;Hm not really sry..there is not much documentation for the TA.&lt;/P&gt;

&lt;P&gt;You might want to start a new answer for that.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 10:05:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Read-logs-from-Microsoft-Windows-Windows-Defender-Operational/m-p/407673#M72290</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2019-01-17T10:05:42Z</dc:date>
    </item>
  </channel>
</rss>

