<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Normalizing imported .evtx files with Splunk Windows Add-on in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Normalizing-imported-evtx-files-with-Splunk-Windows-Add-on/m-p/536264#M89904</link>
    <description>&lt;P&gt;Greetings all,&lt;/P&gt;&lt;P&gt;I'm in a situation where I would like do "offline" Windows event logs analysis, and I need to be able to ingest raw evtx files.&lt;/P&gt;&lt;P&gt;Here is my setup:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Deployed a Windows Splunk instance on a single VM,&lt;/LI&gt;&lt;LI&gt;Installed and configured the &lt;A href="https://splunkbase.splunk.com/app/742/" target="_blank" rel="noopener"&gt;Splunk Add-on for Microsoft Windows&lt;/A&gt; TA.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I'm ingesting the files I need with a "monitor" stanza in the Windows app's inputs.conf:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[monitor://C:\imported_data\evtx]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;disabled = 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;sourcetype = preprocess-winevt&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;index = imported-evtx&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Now, the logs are ingested and parsed and it's already a start (I get proper sourcetypes and everything). &lt;EM&gt;However&lt;/EM&gt;, they do not go through the Windows' app normalizing process, e.g. events don't get populated with the "EventID" field, user names are not parsed into SubjectUserName and TargetUserName fields, things like that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way of making those imported logs properly handled by the TA?&lt;/P&gt;&lt;P&gt;Note: if I try and ingest my local VM's logs with a&amp;nbsp;[WinEventLog://Security] stanza, they are successfully normalized by the app.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Erad&lt;/P&gt;</description>
    <pubDate>Mon, 18 Jan 2021 21:21:21 GMT</pubDate>
    <dc:creator>Erad</dc:creator>
    <dc:date>2021-01-18T21:21:21Z</dc:date>
    <item>
      <title>Normalizing imported .evtx files with Splunk Windows Add-on</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Normalizing-imported-evtx-files-with-Splunk-Windows-Add-on/m-p/536264#M89904</link>
      <description>&lt;P&gt;Greetings all,&lt;/P&gt;&lt;P&gt;I'm in a situation where I would like do "offline" Windows event logs analysis, and I need to be able to ingest raw evtx files.&lt;/P&gt;&lt;P&gt;Here is my setup:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Deployed a Windows Splunk instance on a single VM,&lt;/LI&gt;&lt;LI&gt;Installed and configured the &lt;A href="https://splunkbase.splunk.com/app/742/" target="_blank" rel="noopener"&gt;Splunk Add-on for Microsoft Windows&lt;/A&gt; TA.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I'm ingesting the files I need with a "monitor" stanza in the Windows app's inputs.conf:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[monitor://C:\imported_data\evtx]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;disabled = 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;sourcetype = preprocess-winevt&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;index = imported-evtx&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Now, the logs are ingested and parsed and it's already a start (I get proper sourcetypes and everything). &lt;EM&gt;However&lt;/EM&gt;, they do not go through the Windows' app normalizing process, e.g. events don't get populated with the "EventID" field, user names are not parsed into SubjectUserName and TargetUserName fields, things like that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way of making those imported logs properly handled by the TA?&lt;/P&gt;&lt;P&gt;Note: if I try and ingest my local VM's logs with a&amp;nbsp;[WinEventLog://Security] stanza, they are successfully normalized by the app.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Erad&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 21:21:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Normalizing-imported-evtx-files-with-Splunk-Windows-Add-on/m-p/536264#M89904</guid>
      <dc:creator>Erad</dc:creator>
      <dc:date>2021-01-18T21:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Normalizing imported .evtx files with Splunk Windows Add-on</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Normalizing-imported-evtx-files-with-Splunk-Windows-Add-on/m-p/587958#M103233</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Windows Event Log (.evt) and Windows Event Log XML (.evtx) files that you exported from another Windows machine don't work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.5/Data/Uploaddata" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.5/Data/Uploaddata&lt;/A&gt;&lt;/P&gt;&lt;P&gt;the better way would be-&lt;BR /&gt;1. convert your evtx files to csv&lt;/P&gt;&lt;P&gt;using logparser ( by Microsoft )&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;$logparser = "c:\program files (x86)\Log Parser 2.2\logparser.exe"
$query = "SELECT * INTO c:\logs\logs.csv FROM c:\logs\logs.evtx"

&amp;amp; $logparser -i:evt -o:csv $query&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;2. forward those converted csv file directly to splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 08:04:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Normalizing-imported-evtx-files-with-Splunk-Windows-Add-on/m-p/587958#M103233</guid>
      <dc:creator>human96</dc:creator>
      <dc:date>2022-03-08T08:04:13Z</dc:date>
    </item>
  </channel>
</rss>

