<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic split  windows event log in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/split-windows-event-log/m-p/152539#M97960</link>
    <description>&lt;P&gt;Windows event log, I want to index only part of the message&lt;/P&gt;

&lt;P&gt;exemple &lt;/P&gt;

&lt;P&gt;LogName=Security &lt;BR /&gt;
SourceName=&lt;STRONG&gt;Microsoft Windows security auditing.&lt;/STRONG&gt;&lt;BR /&gt;
EventCode=5447 &lt;BR /&gt;
EventType=0&lt;/P&gt;

&lt;P&gt;SourceName order to index only part of what should you do?&lt;/P&gt;</description>
    <pubDate>Mon, 17 Feb 2014 04:27:45 GMT</pubDate>
    <dc:creator>mrain7</dc:creator>
    <dc:date>2014-02-17T04:27:45Z</dc:date>
    <item>
      <title>split  windows event log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/split-windows-event-log/m-p/152539#M97960</link>
      <description>&lt;P&gt;Windows event log, I want to index only part of the message&lt;/P&gt;

&lt;P&gt;exemple &lt;/P&gt;

&lt;P&gt;LogName=Security &lt;BR /&gt;
SourceName=&lt;STRONG&gt;Microsoft Windows security auditing.&lt;/STRONG&gt;&lt;BR /&gt;
EventCode=5447 &lt;BR /&gt;
EventType=0&lt;/P&gt;

&lt;P&gt;SourceName order to index only part of what should you do?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2014 04:27:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/split-windows-event-log/m-p/152539#M97960</guid>
      <dc:creator>mrain7</dc:creator>
      <dc:date>2014-02-17T04:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: split  windows event log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/split-windows-event-log/m-p/152540#M97961</link>
      <description>&lt;P&gt;If you are running Splunk 6 on your forwarders, there are &lt;A href="http://blogs.splunk.com/2013/10/14/windows-event-logs-in-splunk-6/"&gt;options for filtering&lt;/A&gt; what events and parts of the events you grab.&lt;/P&gt;

&lt;P&gt;Otherwise, you should check out the docs info on how to &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.1/Data/Anonymizedatausingconfigurationfiles"&gt;Anonymize data&lt;/A&gt;, but rather than using the SED props configuration for anonymizing your data, you would be removing the parts you don't want to index.&lt;/P&gt;

&lt;P&gt;HTH,&lt;/P&gt;

&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2014 06:40:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/split-windows-event-log/m-p/152540#M97961</guid>
      <dc:creator>dshpritz</dc:creator>
      <dc:date>2014-02-17T06:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: split  windows event log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/split-windows-event-log/m-p/152541#M97962</link>
      <description>&lt;P&gt;thank you &lt;/P&gt;

&lt;P&gt;but..i need message text hm..&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2014 07:31:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/split-windows-event-log/m-p/152541#M97962</guid>
      <dc:creator>mrain7</dc:creator>
      <dc:date>2014-02-17T07:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: split  windows event log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/split-windows-event-log/m-p/152542#M97963</link>
      <description>&lt;P&gt;I'm sorry, I don't know what you mean by "text hm"&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2014 07:36:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/split-windows-event-log/m-p/152542#M97963</guid>
      <dc:creator>dshpritz</dc:creator>
      <dc:date>2014-02-17T07:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: split  windows event log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/split-windows-event-log/m-p/152543#M97964</link>
      <description>&lt;P&gt;sorry.&lt;/P&gt;

&lt;P&gt;02/17/2014 01:33:30 PM &lt;BR /&gt;
LogName=Security &lt;BR /&gt;
SourceName=Microsoft Windows security auditing. &lt;BR /&gt;
EventCode=4688 &lt;BR /&gt;
EventType=0 &lt;BR /&gt;
Type=정보 &lt;BR /&gt;
ComputerName=NIG-PC &lt;BR /&gt;
TaskCategory=프로세스 만들기 &lt;BR /&gt;
OpCode=정보 &lt;BR /&gt;
RecordNumber=4470383 &lt;BR /&gt;
Keywords=감사 성공 &lt;BR /&gt;
Message=&lt;STRONG&gt;새 프로세스가 만들어져 있습니다.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I want to index the part in bold.&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2014 07:49:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/split-windows-event-log/m-p/152543#M97964</guid>
      <dc:creator>mrain7</dc:creator>
      <dc:date>2014-02-17T07:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: split  windows event log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/split-windows-event-log/m-p/152544#M97965</link>
      <description>&lt;P&gt;No problem. In the props.conf on your indexer or heavy forwarder, you would need to add the following:&lt;/P&gt;

&lt;P&gt;[WinEventLog:Security]&lt;/P&gt;

&lt;P&gt;SED-remove_before_message = (?s).*(?=Message=)&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2014 07:55:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/split-windows-event-log/m-p/152544#M97965</guid>
      <dc:creator>dshpritz</dc:creator>
      <dc:date>2014-02-17T07:55:25Z</dc:date>
    </item>
  </channel>
</rss>

