<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reading WindowsEvent logs from UNC path in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55009#M96860</link>
    <description>&lt;P&gt;All access to the server is firewalled except for the network share where the logs are put as evtx files. I'm not allowed to connect directly to the originator. The files on the share are file dumps from the event log.&lt;/P&gt;</description>
    <pubDate>Sat, 08 Sep 2012 22:55:06 GMT</pubDate>
    <dc:creator>AndreasLP</dc:creator>
    <dc:date>2012-09-08T22:55:06Z</dc:date>
    <item>
      <title>Reading WindowsEvent logs from UNC path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55005#M96856</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have some issues with setting up Splunk to read a WindwsEvent file stored on a network share. It seems like the setup is fine, but no files shows up in Splunk and nothing is indexed.&lt;/P&gt;

&lt;P&gt;From the exact same destination I'm able to read windows update logs without any problems, so it shouldn't be any problems with the credentials. All files have the same permissions.&lt;/P&gt;

&lt;P&gt;Since this is my first tme setting up Splunk I hope i have made some simple misstake which is easily fixed.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2012 21:59:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55005#M96856</guid>
      <dc:creator>AndreasLP</dc:creator>
      <dc:date>2012-09-08T21:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: Reading WindowsEvent logs from UNC path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55006#M96857</link>
      <description>&lt;P&gt;Have you taken a look here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorwindowsdata"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorwindowsdata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2012 22:12:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55006#M96857</guid>
      <dc:creator>neklov_splunk</dc:creator>
      <dc:date>2012-09-08T22:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: Reading WindowsEvent logs from UNC path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55007#M96858</link>
      <description>&lt;P&gt;Unfortunately that access path is restricted, I have only the UNC path to work with &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2012 22:43:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55007#M96858</guid>
      <dc:creator>AndreasLP</dc:creator>
      <dc:date>2012-09-08T22:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: Reading WindowsEvent logs from UNC path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55008#M96859</link>
      <description>&lt;P&gt;What access path is restricted?&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2012 22:49:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55008#M96859</guid>
      <dc:creator>neklov_splunk</dc:creator>
      <dc:date>2012-09-08T22:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: Reading WindowsEvent logs from UNC path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55009#M96860</link>
      <description>&lt;P&gt;All access to the server is firewalled except for the network share where the logs are put as evtx files. I'm not allowed to connect directly to the originator. The files on the share are file dumps from the event log.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2012 22:55:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55009#M96860</guid>
      <dc:creator>AndreasLP</dc:creator>
      <dc:date>2012-09-08T22:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: Reading WindowsEvent logs from UNC path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55010#M96861</link>
      <description>&lt;P&gt;what neklov_splunk was pointing to is the this part of the doc:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.3/Data/MonitorWindowsdata#Index_exported_event_log_.28.evt_or_.evtx.29_files" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.3/Data/MonitorWindowsdata#Index_exported_event_log_.28.evt_or_.evtx.29_files&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:24:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55010#M96861</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2020-09-28T12:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: Reading WindowsEvent logs from UNC path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55011#M96862</link>
      <description>&lt;P&gt;Adding to the above the splunk which has access to the unc path need to be installed on Windows Vista, 7 or Server 2008/2008 R2 to read .evtx&lt;/P&gt;</description>
      <pubDate>Sun, 09 Sep 2012 09:14:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55011#M96862</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-09-09T09:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: Reading WindowsEvent logs from UNC path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55012#M96863</link>
      <description>&lt;P&gt;It turned out I was restricted by a very exotic Group Policy Setting. When that was corrected, everything works fine.&lt;/P&gt;

&lt;P&gt;Thanks for all the answers and quick help!&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2012 12:50:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Reading-WindowsEvent-logs-from-UNC-path/m-p/55012#M96863</guid>
      <dc:creator>AndreasLP</dc:creator>
      <dc:date>2012-09-10T12:50:26Z</dc:date>
    </item>
  </channel>
</rss>

