<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Logs in Endpoint data model in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Windows-Logs-in-Endpoint-data-model/m-p/671415#M9825</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263217"&gt;@sinhashubham014&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I suppose that you are using the Splunk_TA_Windows on the Search Head for parsing.&lt;/P&gt;&lt;P&gt;Anyway, log ingestion isn't managed by ESCU: ESCU contains many Correlation Searches to use in ES or simply in Splunk Enterprise, no parsing or ingesting rules.&lt;/P&gt;&lt;P&gt;See if you are correctly parsing your logs and if there are the eventtypes to assign the correct tagging to your logs, so the DataModels are correctly populated.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 11 Dec 2023 07:43:24 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-12-11T07:43:24Z</dc:date>
    <item>
      <title>Windows Logs in Endpoint data model</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Windows-Logs-in-Endpoint-data-model/m-p/671409#M9824</link>
      <description>&lt;P&gt;Hello, i am deploying the ESCU searches in our environment. However, the endpoint logs are not ingested in Splunk. However for deploying the usecases, I ingested the Windws Security Logs with win event 4688/4689 to monitor the usecases. Sysmon logs are not ingested well. The Windows logs, configured with endpoint model are triggering the notables. Is it triggered notables relevant with the incident triage?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 07:16:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Windows-Logs-in-Endpoint-data-model/m-p/671409#M9824</guid>
      <dc:creator>sinhashubham014</dc:creator>
      <dc:date>2023-12-11T07:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Logs in Endpoint data model</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Windows-Logs-in-Endpoint-data-model/m-p/671415#M9825</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263217"&gt;@sinhashubham014&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I suppose that you are using the Splunk_TA_Windows on the Search Head for parsing.&lt;/P&gt;&lt;P&gt;Anyway, log ingestion isn't managed by ESCU: ESCU contains many Correlation Searches to use in ES or simply in Splunk Enterprise, no parsing or ingesting rules.&lt;/P&gt;&lt;P&gt;See if you are correctly parsing your logs and if there are the eventtypes to assign the correct tagging to your logs, so the DataModels are correctly populated.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 07:43:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Windows-Logs-in-Endpoint-data-model/m-p/671415#M9825</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-12-11T07:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Logs in Endpoint data model</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Windows-Logs-in-Endpoint-data-model/m-p/671418#M9826</link>
      <description>&lt;P&gt;I have configured the Endpoint data model logs with windows:security, system and registery logs. However, when i triggered the ESCU usecases, it's showing the events.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 08:03:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Windows-Logs-in-Endpoint-data-model/m-p/671418#M9826</guid>
      <dc:creator>sinhashubham014</dc:creator>
      <dc:date>2023-12-11T08:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Logs in Endpoint data model</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Windows-Logs-in-Endpoint-data-model/m-p/671424#M9827</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263217"&gt;@sinhashubham014&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;which ESCU Use Cases are triggered?&lt;/P&gt;&lt;P&gt;Why isn't the result you want?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 09:05:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Windows-Logs-in-Endpoint-data-model/m-p/671424#M9827</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-12-11T09:05:04Z</dc:date>
    </item>
  </channel>
</rss>

