<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I index only my application data from windows event logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-only-my-application-data-from-windows-event-logs/m-p/391170#M94136</link>
    <description>&lt;P&gt;hi @madhufuture,&lt;/P&gt;

&lt;P&gt;Did either of the answers below solve your problem? If so, please resolve this post by approving one of them. &lt;BR /&gt;
If your problem is still not solved, keep us updated so that someone else can help ya.&lt;/P&gt;

&lt;P&gt;Thanks for posting!&lt;/P&gt;</description>
    <pubDate>Wed, 26 Sep 2018 00:11:07 GMT</pubDate>
    <dc:creator>mstjohn_splunk</dc:creator>
    <dc:date>2018-09-26T00:11:07Z</dc:date>
    <item>
      <title>How do I index only my application data from windows event logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-only-my-application-data-from-windows-event-logs/m-p/391167#M94133</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have an application &lt;STRONG&gt;ABC&lt;/STRONG&gt;. From application &lt;STRONG&gt;ABC&lt;/STRONG&gt; , I'm writing my logs to Windows &lt;EM&gt;Application&lt;/EM&gt; Event logs. I want to index only my ABC application logs, not complete my windows event logs.&lt;/P&gt;

&lt;P&gt;Could you please help me figure out how I can index specific application event logs?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Sep 2018 23:45:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-only-my-application-data-from-windows-event-logs/m-p/391167#M94133</guid>
      <dc:creator>madhufuture</dc:creator>
      <dc:date>2018-09-24T23:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: How do I index only my application data from windows event logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-only-my-application-data-from-windows-event-logs/m-p/391168#M94134</link>
      <description>&lt;P&gt;You can filter by setting a unique event ID in the application log.&lt;/P&gt;

&lt;P&gt;inputs.conf:　whitelist&lt;BR /&gt;
Whether to index events that match the specified text string. This attribute is optional.&lt;BR /&gt;
You can specify one of two formats:&lt;/P&gt;

&lt;P&gt;One or more Event Log event codes or event IDs (Event Code/ID format.)&lt;BR /&gt;
One or more sets of keys and regular expressions (Advanced filtering format.)&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 04:20:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-only-my-application-data-from-windows-event-logs/m-p/391168#M94134</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2018-09-25T04:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: How do I index only my application data from windows event logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-only-my-application-data-from-windows-event-logs/m-p/391169#M94135</link>
      <description>&lt;P&gt;Basically, when you are writing out your application logs, you need to mark them in some way so that they can be easily identified.  &lt;/P&gt;

&lt;P&gt;Then, you blacklist all incoming events, and whitelist only those that match your application logs.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 14:27:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-only-my-application-data-from-windows-event-logs/m-p/391169#M94135</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2018-09-25T14:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: How do I index only my application data from windows event logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-only-my-application-data-from-windows-event-logs/m-p/391170#M94136</link>
      <description>&lt;P&gt;hi @madhufuture,&lt;/P&gt;

&lt;P&gt;Did either of the answers below solve your problem? If so, please resolve this post by approving one of them. &lt;BR /&gt;
If your problem is still not solved, keep us updated so that someone else can help ya.&lt;/P&gt;

&lt;P&gt;Thanks for posting!&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 00:11:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-only-my-application-data-from-windows-event-logs/m-p/391170#M94136</guid>
      <dc:creator>mstjohn_splunk</dc:creator>
      <dc:date>2018-09-26T00:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: How do I index only my application data from windows event logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-only-my-application-data-from-windows-event-logs/m-p/391171#M94137</link>
      <description>&lt;P&gt;Perfect!! Thanks for your help&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 22:38:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-index-only-my-application-data-from-windows-event-logs/m-p/391171#M94137</guid>
      <dc:creator>madhufuture</dc:creator>
      <dc:date>2018-09-26T22:38:55Z</dc:date>
    </item>
  </channel>
</rss>

