<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting Up Splunk Universal Forwarder to Monitor and Analyze .evtx Files in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Setting-Up-Splunk-Universal-Forwarder-to-Monitor-and-Analyze/m-p/698803#M12060</link>
    <description>&lt;P&gt;I have 1 TB of data that I want to analyze. Will TA_eventgenb be accepted?&lt;/P&gt;</description>
    <pubDate>Wed, 11 Sep 2024 14:44:43 GMT</pubDate>
    <dc:creator>tuts</dc:creator>
    <dc:date>2024-09-11T14:44:43Z</dc:date>
    <item>
      <title>Setting Up Splunk Universal Forwarder to Monitor and Analyze .evtx Files</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Setting-Up-Splunk-Universal-Forwarder-to-Monitor-and-Analyze/m-p/698741#M12057</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello Splunk Community,&lt;/P&gt;&lt;P&gt;I have .evtx files from several devices, and I would like to analyze them using Splunk Universal Forwarder (the agent). I want to set up the agent to continuously monitor these files as if the data is live, so that I can apply Splunk Enterprise Security (ES) rules to them.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 07:44:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Setting-Up-Splunk-Universal-Forwarder-to-Monitor-and-Analyze/m-p/698741#M12057</guid>
      <dc:creator>tuts</dc:creator>
      <dc:date>2024-09-11T07:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Up Splunk Universal Forwarder to Monitor and Analyze .evtx Files</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Setting-Up-Splunk-Universal-Forwarder-to-Monitor-and-Analyze/m-p/698751#M12058</link>
      <description>&lt;P&gt;1. While I think I've read somewhere some dirty tricks to import the events from evtx file, it's not something that's normally done. Usually you monitor the eventlog channels, not the evt(x) files themselves.&lt;/P&gt;&lt;P&gt;2. If you want to simulate a live system, it's usually not enough to ingest a batch of events from some earlier-gathered dump since the events will get indexed in the past. For such simulation stuff you usually use event generators like TA_eventgen.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 09:17:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Setting-Up-Splunk-Universal-Forwarder-to-Monitor-and-Analyze/m-p/698751#M12058</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-09-11T09:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Up Splunk Universal Forwarder to Monitor and Analyze .evtx Files</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Setting-Up-Splunk-Universal-Forwarder-to-Monitor-and-Analyze/m-p/698803#M12060</link>
      <description>&lt;P&gt;I have 1 TB of data that I want to analyze. Will TA_eventgenb be accepted?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 14:44:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Setting-Up-Splunk-Universal-Forwarder-to-Monitor-and-Analyze/m-p/698803#M12060</guid>
      <dc:creator>tuts</dc:creator>
      <dc:date>2024-09-11T14:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Up Splunk Universal Forwarder to Monitor and Analyze .evtx Files</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Setting-Up-Splunk-Universal-Forwarder-to-Monitor-and-Analyze/m-p/698833#M12061</link>
      <description>&lt;P&gt;No. It's not how not how it works. You wrote that you want to simulate a live system. That usually means continuous generation of events and reacting to them as they are ingested.&lt;/P&gt;&lt;P&gt;TA_eventgen does just that - it creates events based on configuration and templates.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 20:48:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Setting-Up-Splunk-Universal-Forwarder-to-Monitor-and-Analyze/m-p/698833#M12061</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-09-11T20:48:17Z</dc:date>
    </item>
  </channel>
</rss>

