<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor evtx log in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119136#M7637</link>
    <description>&lt;P&gt;I am currently having this same issue.  Were you able to solve the problem?  I have changed my CHARSET=UTF-16LE on my UF and no luck.  Really looking for an answer on this one.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Sep 2015 20:59:04 GMT</pubDate>
    <dc:creator>Sarmbrister</dc:creator>
    <dc:date>2015-09-16T20:59:04Z</dc:date>
    <item>
      <title>Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119119#M7620</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;

&lt;P&gt;I need to drag a evtx log from %SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-PrintService.evtx&lt;/P&gt;

&lt;P&gt;This needs to show all the indivdual print jobs/ info&lt;/P&gt;

&lt;P&gt;This needs to be completed in a conf file, currently looking like this  - &lt;/P&gt;

&lt;P&gt;[WinEventLog://C:\Windows\System32\Winevt\Logs\Microsoft-Windows-PrintService%4Operational.evtx&lt;BR /&gt;
disabled = false&lt;BR /&gt;
sourcetype = printname&lt;/P&gt;

&lt;P&gt;currently the results look a little like this - &lt;/P&gt;

&lt;P&gt;x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\&lt;/P&gt;

&lt;P&gt;Can anyone help me please ?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 13:44:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119119#M7620</guid>
      <dc:creator>AaronMoorcroft</dc:creator>
      <dc:date>2014-04-03T13:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119120#M7621</link>
      <description>&lt;P&gt;Hi AaronMoorcroft,&lt;/P&gt;

&lt;P&gt;could it be that you have set a &lt;CODE&gt;TCP&lt;/CODE&gt; input port in &lt;CODE&gt;inputs.conf&lt;/CODE&gt; on the indexer like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcp://any TCP Port]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;...should be instead :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[splunktcp://9997]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The indexer is receiving cooked data on a TCP port configured to receive uncooked data. Port 9997 is the default port for Splunk to receive cooked data.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 13:52:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119120#M7621</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-04-03T13:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119121#M7622</link>
      <description>&lt;P&gt;Is this log file being read on the machine that produced it?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 13:53:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119121#M7622</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-04-03T13:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119122#M7623</link>
      <description>&lt;P&gt;Hi Luke, &lt;/P&gt;

&lt;P&gt;no the the file is on a different server and is being forwarded with the universal forwarder to our main indexer&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 13:55:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119122#M7623</guid>
      <dc:creator>AaronMoorcroft</dc:creator>
      <dc:date>2014-04-03T13:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119123#M7624</link>
      <description>&lt;P&gt;No i have no setup like that within the inputs file other than the default host name&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 13:56:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119123#M7624</guid>
      <dc:creator>AaronMoorcroft</dc:creator>
      <dc:date>2014-04-03T13:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119124#M7625</link>
      <description>&lt;P&gt;how did you setup receiving on the indexer in this case? Since you are forwarding this from an universal forwarder?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 14:01:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119124#M7625</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-04-03T14:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119125#M7626</link>
      <description>&lt;P&gt;you could try the CHARSET option in props.conf on the forwarder or read this &lt;A href="http://answers.splunk.com/answers/83790/how-do-i-remove-x00-characters-from-my-log-message"&gt;http://answers.splunk.com/answers/83790/how-do-i-remove-x00-characters-from-my-log-message&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 14:07:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119125#M7626</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-04-03T14:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119126#M7627</link>
      <description>&lt;P&gt;All events would be sent via 9997 from all our lets call them mini forwarders onto lets call it our main forwarder and that then onto the indexer.&lt;/P&gt;

&lt;P&gt;this is working perfectly well for all other logs and configs that are set up, I suspect this is somthing to do with this being an evtx file&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 14:08:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119126#M7627</guid>
      <dc:creator>AaronMoorcroft</dc:creator>
      <dc:date>2014-04-03T14:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119127#M7628</link>
      <description>&lt;P&gt;With windows logs, they need to be read on the same version of windows as the system that created the log file.  If you try to read an evtx file on a w2k3 server, you'll probably get data like you have.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 14:16:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119127#M7628</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-04-03T14:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119128#M7629</link>
      <description>&lt;P&gt;ok that would make perfect sense but in that case how do the regular event logs work as they are fine ??&lt;/P&gt;

&lt;P&gt;very confusing&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 14:19:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119128#M7629</guid>
      <dc:creator>AaronMoorcroft</dc:creator>
      <dc:date>2014-04-03T14:19:08Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119129#M7630</link>
      <description>&lt;P&gt;What do you mean by regular?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 14:25:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119129#M7630</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-04-03T14:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119130#M7631</link>
      <description>&lt;P&gt;Application&lt;BR /&gt;
Security&lt;BR /&gt;
System&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 14:26:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119130#M7631</guid>
      <dc:creator>AaronMoorcroft</dc:creator>
      <dc:date>2014-04-03T14:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119131#M7632</link>
      <description>&lt;P&gt;If they are evtx, and they are being read on w2k3 without issue then that is a good question.  I did not think that was possible.  See the bottom of this doc:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.2/Data/MonitorWindowsdata"&gt;http://docs.splunk.com/Documentation/Splunk/6.0.2/Data/MonitorWindowsdata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 14:37:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119131#M7632</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-04-03T14:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119132#M7633</link>
      <description>&lt;P&gt;I may have found a way around this, ill post back when an answer, maybe tomorrow now though, what im thinking is move the specific logs from that event log into the system event log...&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 14:46:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119132#M7633</guid>
      <dc:creator>AaronMoorcroft</dc:creator>
      <dc:date>2014-04-03T14:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119133#M7634</link>
      <description>&lt;P&gt;Not sure if everyone would class this as an answer however I have managed to find a work around that may work for someone else out there.&lt;/P&gt;

&lt;P&gt;So in Server 08 I guess not all events are automagically logged in either System, Application or Security the 3 main places you look for your logs (yes i know there are a few others)&lt;/P&gt;

&lt;P&gt;anyway when enabling the printer logs this goes into a seperate location altogeather see the loaction listed in the initial question, basically what I have done is changed the properties of that log location to point to the System log location, in doing this it duplicates the logs, the logs will continue to go to the original location and there will then also be a copy put into in this case the system log too.&lt;/P&gt;

&lt;P&gt;for me this has resolved my problem as splunk was picking up logs from the 3 main locations but not the other...&lt;/P&gt;

&lt;P&gt;thanks for your help Luke and Mus.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 16:30:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119133#M7634</guid>
      <dc:creator>AaronMoorcroft</dc:creator>
      <dc:date>2014-04-03T16:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119134#M7635</link>
      <description>&lt;P&gt;Just as a follow up the answer above worked hoever only spradically, very on and off, finally manged to get it working with the below in the conf file - &lt;/P&gt;

&lt;P&gt;[WinEventLog:Microsoft-Windows-PrintService/Operational]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;/P&gt;

&lt;P&gt;initially this wouldnt work but after a few hours and a couple of splunk service restarts it all came to life. &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:21:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119134#M7635</guid>
      <dc:creator>AaronMoorcroft</dc:creator>
      <dc:date>2020-09-28T16:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119135#M7636</link>
      <description>&lt;P&gt;Splunk will show a sourcetype of preprocess-winevt on the preview screen while giving you the raw file output.  This is normal.  Click through all the rest of the adding data prompts and then splunk will send the files through the correct processor to index the events&lt;/P&gt;</description>
      <pubDate>Sun, 19 Apr 2015 16:19:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119135#M7636</guid>
      <dc:creator>jeubank12</dc:creator>
      <dc:date>2015-04-19T16:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119136#M7637</link>
      <description>&lt;P&gt;I am currently having this same issue.  Were you able to solve the problem?  I have changed my CHARSET=UTF-16LE on my UF and no luck.  Really looking for an answer on this one.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2015 20:59:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119136#M7637</guid>
      <dc:creator>Sarmbrister</dc:creator>
      <dc:date>2015-09-16T20:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119137#M7638</link>
      <description>&lt;P&gt;I have been dealing with this same issue for a long time I think i figured out the issue.  Since it is windows event logs and they are in binary Splunk might not know how to bring them in unless they are part of the wineventlog configs or the data needs to be in plain text.  I am currently working on a script to put the data into plain text then have splunk read that file then delete the plain text file after splunk pulls the data.  If successful I'll let you know.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2015 00:23:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119137#M7638</guid>
      <dc:creator>Sarmbrister</dc:creator>
      <dc:date>2015-09-23T00:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor evtx log</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119138#M7639</link>
      <description>&lt;P&gt;I am dealing with the same issue.  One of two things might work for this.&lt;BR /&gt;&lt;BR /&gt;
 1. When you run a search use this rex command.      index= | rex mode=sed "s/\\x..//g"   (This will remove all of the null data or anything that has \x and any two characters after it.&lt;BR /&gt;
 2. If you are continuing to index from the source then set up a transforms.conf file and set up the props.conf.  regex to use   s/\\x..//g&lt;/P&gt;

&lt;P&gt;I set up the transforms.conf file and am currently waiting on data to flow through to determine if it is working.&lt;/P&gt;

&lt;P&gt;Transforms.conf:  &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1/admin/Transformsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.1/admin/Transformsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Props.conf:  &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/admin/Propsconf"&gt;http://docs.splunk.com/Documentation/Splunk/latest/admin/Propsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 16:26:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-evtx-log/m-p/119138#M7639</guid>
      <dc:creator>Sarmbrister</dc:creator>
      <dc:date>2015-11-11T16:26:45Z</dc:date>
    </item>
  </channel>
</rss>

