<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stanza for to ingest logs from specific date in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Stanza-for-to-ingest-logs-from-specific-date/m-p/542563#M90643</link>
    <description>&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;ignoreOlderThan&lt;/FONT&gt; setting is for monitor inputs, not &lt;FONT face="courier new,courier"&gt;WinEventLog&lt;/FONT&gt;.&amp;nbsp; I'm not aware of a setting that controls how far back into the event log the forwarder will read.&lt;/P&gt;</description>
    <pubDate>Fri, 05 Mar 2021 14:29:04 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-03-05T14:29:04Z</dc:date>
    <item>
      <title>Stanza for to ingest logs from specific date</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Stanza-for-to-ingest-logs-from-specific-date/m-p/542539#M90641</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;I want the stanza to ingest logs from a specific date in Linux or Window environment.&lt;/P&gt;&lt;P&gt;Currently am using windows &lt;STRONG&gt;(ignoreOlderThan = 365d)&amp;nbsp;&lt;/STRONG&gt;and the same using for Linux it's not working.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Requirement&lt;/STRONG&gt;: I want to ingest logs from Linux via UF and windows machines to Splunk, so I want only 356days or 180days. Can anyone share other than the above stanza?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Example:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;[WinEventLog://Security]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = trendmicro&lt;BR /&gt;sourcetype = %trendmicro%&lt;BR /&gt;ignoreOlderThan = 365d&lt;BR /&gt;whitelist = 4625,4648,4723,4728,4732,4740,4777,5031,4624,4634&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 11:27:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Stanza-for-to-ingest-logs-from-specific-date/m-p/542539#M90641</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2021-03-05T11:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Stanza for to ingest logs from specific date</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Stanza-for-to-ingest-logs-from-specific-date/m-p/542563#M90643</link>
      <description>&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;ignoreOlderThan&lt;/FONT&gt; setting is for monitor inputs, not &lt;FONT face="courier new,courier"&gt;WinEventLog&lt;/FONT&gt;.&amp;nbsp; I'm not aware of a setting that controls how far back into the event log the forwarder will read.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 14:29:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Stanza-for-to-ingest-logs-from-specific-date/m-p/542563#M90643</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-05T14:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: Stanza for to ingest logs from specific date</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Stanza-for-to-ingest-logs-from-specific-date/m-p/542568#M90644</link>
      <description>&lt;P&gt;Hello Rich,&lt;/P&gt;&lt;P&gt;If that is not the case, can you please which stanza can I use for my question?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 15:11:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Stanza-for-to-ingest-logs-from-specific-date/m-p/542568#M90644</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2021-03-05T15:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: Stanza for to ingest logs from specific date</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Stanza-for-to-ingest-logs-from-specific-date/m-p/542569#M90645</link>
      <description>&lt;P&gt;please suggest some stanzas to find out the way.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 15:12:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Stanza-for-to-ingest-logs-from-specific-date/m-p/542569#M90645</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2021-03-05T15:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: Stanza for to ingest logs from specific date</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Stanza-for-to-ingest-logs-from-specific-date/m-p/542612#M90653</link>
      <description>&lt;P&gt;As I said in my original answer, I'm not aware of ANY settings that do what you want.&lt;/P&gt;&lt;P&gt;However, ingestion of older events is a one-time happening so why not just let it happen?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 17:47:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Stanza-for-to-ingest-logs-from-specific-date/m-p/542612#M90653</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-05T17:47:38Z</dc:date>
    </item>
  </channel>
</rss>

