<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic continuously monitor any  local event Log windows 10 in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/continuously-monitor-any-local-event-Log-windows-10/m-p/297958#M5534</link>
    <description>&lt;P&gt;I am a data  analyst interested in Security that have been  reccently introduced to Splunk that I am learning on my own now. I was wondering how  I can monitor any event  on the &lt;STRONG&gt;local event Log&lt;/STRONG&gt; ? here is what I do : &lt;BR /&gt;
&lt;BR /&gt;I go to the &lt;STRONG&gt;local event log&lt;/STRONG&gt; after clicking the Monitoring option,  then  select &lt;STRONG&gt;System&lt;/STRONG&gt;. In the &lt;STRONG&gt;input settings&lt;/STRONG&gt; I change the &lt;STRONG&gt;app context&lt;/STRONG&gt;  from &lt;STRONG&gt;Search &amp;amp; Reports&lt;/STRONG&gt; to &lt;STRONG&gt;Monitor console&lt;/STRONG&gt;. The events looks structured  when I am done , but nothing is appearing on the visualisation  tab;&lt;/P&gt;

&lt;P&gt;How can I have a visualisation of my monitoring. I do not mind monitoring anything else; I just need  to see the graph. I guess  &lt;/P&gt;</description>
    <pubDate>Sun, 19 Nov 2017 15:02:35 GMT</pubDate>
    <dc:creator>YANN84</dc:creator>
    <dc:date>2017-11-19T15:02:35Z</dc:date>
    <item>
      <title>continuously monitor any  local event Log windows 10</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/continuously-monitor-any-local-event-Log-windows-10/m-p/297958#M5534</link>
      <description>&lt;P&gt;I am a data  analyst interested in Security that have been  reccently introduced to Splunk that I am learning on my own now. I was wondering how  I can monitor any event  on the &lt;STRONG&gt;local event Log&lt;/STRONG&gt; ? here is what I do : &lt;BR /&gt;
&lt;BR /&gt;I go to the &lt;STRONG&gt;local event log&lt;/STRONG&gt; after clicking the Monitoring option,  then  select &lt;STRONG&gt;System&lt;/STRONG&gt;. In the &lt;STRONG&gt;input settings&lt;/STRONG&gt; I change the &lt;STRONG&gt;app context&lt;/STRONG&gt;  from &lt;STRONG&gt;Search &amp;amp; Reports&lt;/STRONG&gt; to &lt;STRONG&gt;Monitor console&lt;/STRONG&gt;. The events looks structured  when I am done , but nothing is appearing on the visualisation  tab;&lt;/P&gt;

&lt;P&gt;How can I have a visualisation of my monitoring. I do not mind monitoring anything else; I just need  to see the graph. I guess  &lt;/P&gt;</description>
      <pubDate>Sun, 19 Nov 2017 15:02:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/continuously-monitor-any-local-event-Log-windows-10/m-p/297958#M5534</guid>
      <dc:creator>YANN84</dc:creator>
      <dc:date>2017-11-19T15:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: continuously monitor any  local event Log windows 10</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/continuously-monitor-any-local-event-Log-windows-10/m-p/297959#M5535</link>
      <description>&lt;P&gt;What kind of graph is necessary?&lt;BR /&gt;
Please check how to use STATS, CHART, TIMECHART etc.&lt;/P&gt;

&lt;P&gt;ex.&lt;BR /&gt;
sourcetype="WinEventLog:System"|timechart count by EventCode&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 04:53:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/continuously-monitor-any-local-event-Log-windows-10/m-p/297959#M5535</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2017-11-20T04:53:50Z</dc:date>
    </item>
  </channel>
</rss>

