<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows Event Log - .evtx file import - Foriegn AD Domain in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Log-evtx-file-import-Foriegn-AD-Domain/m-p/557628#M92283</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Hoping to get a hint on where to go with this;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Use Case:&amp;nbsp;&lt;/STRONG&gt;I am attempting to import files from a exported .evtx file from a external Windows host as per:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A title="Splunk Docs for Importing Windows Event Log Files" href="https://docs.splunk.com/Documentation/Splunk/7.3.3/Data/MonitorWindowseventlogdata#Index_exported_event_log_.28.evt_or_.evtx.29_files" target="_self"&gt;Splunk Docs for Importing Windows Event Log Files&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The inputs.conf has been written close to the following.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor://D:\SplunkLogImport\awesome_hostname\preprocess-winevt\*.evtx]
disabled = 0
sourcetype = preprocess-winevt
host = awesome_hostname
index = awesome_index
crcSalt = &amp;lt;SOURCE&amp;gt;
move_policy = sinkhole
evt_resolve_ad_obj = 0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The challenge here is the logs are from a server in another domain from another network entirely and I have no access to a domain controller.&lt;BR /&gt;&lt;BR /&gt;As per:&amp;nbsp;&lt;BR /&gt;&lt;A title="Splunk Docs for Monitor Windows EventLog Data" href="https://docs.splunk.com/Documentation/Splunk/7.3.2/Data/MonitorWindowseventlogdata#How_the_Windows_Event_Log_monitor_interacts_with_Active_Directory_.28AD.29" target="_self"&gt;Splunk Docs for Monitor Windows EventLog Data&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am recieving an error (as expected) but I'm not seeing any data come in.&amp;nbsp; I am not concerned with having all the data resolved and seeking to simply input this data.&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Question:&lt;/STRONG&gt; Any thoughts on how to blindly import the event logs knowing full well we're not going to get SID/GID object resolution?&amp;nbsp; What is required to tell the forwarder not to bind to the domain?&amp;nbsp; I've attempted&amp;nbsp; the following with no results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;evt_resolve_ad_obj = 0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would appreciate any guidance that may exist on this subject.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Details:&lt;BR /&gt;&lt;/STRONG&gt;Host is running Splunk Universal Forwarder v 7.3 on Windows 2012.&amp;nbsp; Source data is from a Windows 2008 R2 server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The Error:&amp;nbsp;&lt;/STRONG&gt;&lt;EM&gt;(thousands of these)&lt;/EM&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;INFO WinEventLogChannel - WinEventLogChannel::getEventsNew (2000): No bindToDc&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jun 2021 15:03:18 GMT</pubDate>
    <dc:creator>dsctm3</dc:creator>
    <dc:date>2021-06-29T15:03:18Z</dc:date>
    <item>
      <title>Windows Event Log - .evtx file import - Foriegn AD Domain</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Log-evtx-file-import-Foriegn-AD-Domain/m-p/557628#M92283</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Hoping to get a hint on where to go with this;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Use Case:&amp;nbsp;&lt;/STRONG&gt;I am attempting to import files from a exported .evtx file from a external Windows host as per:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A title="Splunk Docs for Importing Windows Event Log Files" href="https://docs.splunk.com/Documentation/Splunk/7.3.3/Data/MonitorWindowseventlogdata#Index_exported_event_log_.28.evt_or_.evtx.29_files" target="_self"&gt;Splunk Docs for Importing Windows Event Log Files&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The inputs.conf has been written close to the following.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor://D:\SplunkLogImport\awesome_hostname\preprocess-winevt\*.evtx]
disabled = 0
sourcetype = preprocess-winevt
host = awesome_hostname
index = awesome_index
crcSalt = &amp;lt;SOURCE&amp;gt;
move_policy = sinkhole
evt_resolve_ad_obj = 0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The challenge here is the logs are from a server in another domain from another network entirely and I have no access to a domain controller.&lt;BR /&gt;&lt;BR /&gt;As per:&amp;nbsp;&lt;BR /&gt;&lt;A title="Splunk Docs for Monitor Windows EventLog Data" href="https://docs.splunk.com/Documentation/Splunk/7.3.2/Data/MonitorWindowseventlogdata#How_the_Windows_Event_Log_monitor_interacts_with_Active_Directory_.28AD.29" target="_self"&gt;Splunk Docs for Monitor Windows EventLog Data&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am recieving an error (as expected) but I'm not seeing any data come in.&amp;nbsp; I am not concerned with having all the data resolved and seeking to simply input this data.&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Question:&lt;/STRONG&gt; Any thoughts on how to blindly import the event logs knowing full well we're not going to get SID/GID object resolution?&amp;nbsp; What is required to tell the forwarder not to bind to the domain?&amp;nbsp; I've attempted&amp;nbsp; the following with no results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;evt_resolve_ad_obj = 0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would appreciate any guidance that may exist on this subject.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Details:&lt;BR /&gt;&lt;/STRONG&gt;Host is running Splunk Universal Forwarder v 7.3 on Windows 2012.&amp;nbsp; Source data is from a Windows 2008 R2 server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The Error:&amp;nbsp;&lt;/STRONG&gt;&lt;EM&gt;(thousands of these)&lt;/EM&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;INFO WinEventLogChannel - WinEventLogChannel::getEventsNew (2000): No bindToDc&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 15:03:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Log-evtx-file-import-Foriegn-AD-Domain/m-p/557628#M92283</guid>
      <dc:creator>dsctm3</dc:creator>
      <dc:date>2021-06-29T15:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Log - .evtx file import - Foriegn AD Domain</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Log-evtx-file-import-Foriegn-AD-Domain/m-p/557631#M92284</link>
      <description>&lt;P&gt;So I found the solution, and as usual "It was dumb"&lt;BR /&gt;&lt;BR /&gt;The resolution was that the hostname field was ignored by the input for some reason and the data got processed as the actual hostname of the host, not the name I gave it.&amp;nbsp; &amp;nbsp;When I search for the actual hostname the logs have been ingested despite the warning about DC binds.&lt;BR /&gt;&lt;BR /&gt;I suppose when you use that sourcetype Splunk ingests the data and runs it through the TA as it came from a native forwarder.&amp;nbsp; I suspect some of the data might be missing, but I'm willing to accept that given the lack of resolution.&lt;BR /&gt;&lt;BR /&gt;Marking this solved for now.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 15:35:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Log-evtx-file-import-Foriegn-AD-Domain/m-p/557631#M92284</guid>
      <dc:creator>dsctm3</dc:creator>
      <dc:date>2021-06-29T15:35:26Z</dc:date>
    </item>
  </channel>
</rss>

