<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XML Event Viewer Data Missing Message\Fields in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596584#M48917</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am not seeing any non-binary setting for Event Viewer data.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 05 May 2022 17:13:24 GMT</pubDate>
    <dc:creator>VTARNG_Paul</dc:creator>
    <dc:date>2022-05-05T17:13:24Z</dc:date>
    <item>
      <title>XML Event Viewer Data Missing Message\Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596495#M48908</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I was hoping that modification of KV_Mode=xml in props.conf under the [xmlwineventlog] stanza on the standalone index\search head\deployment server would properly parse the Event View data from servers, but unfortunately I am not seeing all the message data that should be included.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is sample of data, please see &lt;A href="https://ngvt-sb6p-04:8000/en-US/app/search/search?q=search%20index%3Dwineventlog%20sourcetype%3D*%20EventCode%3D6013%7C%20rex%20field%3DMessage%20%22uptime%20is%20(%3F%3Cuptime%3E%5Cd%2B)%20seconds%22%20%20%20%7C%20eval%20Uptime_Minutes%3Duptime%2F60%20%20%20%7C%20eval%20LastBoot%3D_time-uptime%20%20%20%7C%20convert%20ctime(LastBoot)%20%7C%20table%20%20_time%2C%20host%2C%20Message%2C%20EventCode%2C%20uptime%2C%20Uptime_Minutes%2C%20LastBoot&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-24h%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=statistics&amp;amp;display.visualizations.show=0&amp;amp;s=%2FservicesNS%2Fadm_paul.j.bugeja%2Fsearch%2Fsaved%2Fsearches%2FUptime&amp;amp;sid=1651749770.286#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Event.EventData.Binary&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;field:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VTARNG_Paul_0-1651750719929.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19441i61F2AB6AF8E7DC7F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VTARNG_Paul_0-1651750719929.png" alt="VTARNG_Paul_0-1651750719929.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 11:55:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596495#M48908</guid>
      <dc:creator>VTARNG_Paul</dc:creator>
      <dc:date>2022-05-05T11:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: XML Event Viewer Data Missing Message\Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596512#M48910</link>
      <description>&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;KV_Mode=xml&lt;/FONT&gt; setting will have no effect on that data since it is not in XML format.&lt;/P&gt;&lt;P&gt;Check the source application to see if there is a setting that will change the format to something non-binary.&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 13:19:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596512#M48910</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-05-05T13:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: XML Event Viewer Data Missing Message\Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596566#M48914</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245466"&gt;@VTARNG_Paul&lt;/a&gt;&amp;nbsp;- Please look at the same event in Windows Event Viewer on the machine and see how you are seeing the fields and data.&lt;/P&gt;&lt;P&gt;Ideally, Splunk collects what is generated on the system.&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 16:40:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596566#M48914</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-05-05T16:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: XML Event Viewer Data Missing Message\Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596583#M48916</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;From sourcetype XmlWinEventLog we are missing the data in these Event Viewer fields located in the General tab in this screenshot.&amp;nbsp; For example TaskCategory and Keywords.&lt;/P&gt;&lt;P&gt;It should be included as we are pulling the identical data from another server with sourcetype WinEventLog and all of those fields are in the events.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VTARNG_Paul_0-1651770503624.png" style="width: 652px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19460i09AE313DAFD4E1F1/image-dimensions/652x424?v=v2" width="652" height="424" role="button" title="VTARNG_Paul_0-1651770503624.png" alt="VTARNG_Paul_0-1651770503624.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 17:12:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596583#M48916</guid>
      <dc:creator>VTARNG_Paul</dc:creator>
      <dc:date>2022-05-05T17:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: XML Event Viewer Data Missing Message\Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596584#M48917</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am not seeing any non-binary setting for Event Viewer data.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 17:13:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596584#M48917</guid>
      <dc:creator>VTARNG_Paul</dc:creator>
      <dc:date>2022-05-05T17:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: XML Event Viewer Data Missing Message\Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596585#M48918</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245466"&gt;@VTARNG_Paul&lt;/a&gt;&amp;nbsp;- Your Event Viewer should also show other sections as well for XML.&lt;/P&gt;&lt;P&gt;This screenshot is what PlainText formatted is what you can get in Splunk if you enable PlainText format event with inputs.conf.&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 17:15:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596585#M48918</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-05-05T17:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: XML Event Viewer Data Missing Message\Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596600#M48919</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You are correct the Message field is not included and other fields that I would like to use have generic names, Data, which is not very helpful for the reports/dashboard I want to make.&lt;/P&gt;&lt;P&gt;We are using xml because it requires less storage space and possibly faster, but have not really seen any performance advantage from my testing so far.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think we might have to rethink the xml version of that data.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VTARNG_Paul_0-1651775777525.png" style="width: 756px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19462i7D1332A12E793D2B/image-dimensions/756x544?v=v2" width="756" height="544" role="button" title="VTARNG_Paul_0-1651775777525.png" alt="VTARNG_Paul_0-1651775777525.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers, Paul&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 18:37:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596600#M48919</guid>
      <dc:creator>VTARNG_Paul</dc:creator>
      <dc:date>2022-05-05T18:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: XML Event Viewer Data Missing Message\Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596667#M48921</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245466"&gt;@VTARNG_Paul&lt;/a&gt;&amp;nbsp;- That's the problem with Windows I always face is that XML data (which is a new version) is not always a replica of PlainText (Legacy) format.&lt;/P&gt;&lt;P&gt;My views:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Collect PlainText - WinEventLog:Security, WinEventLog:System, etc&lt;/LI&gt;&lt;LI&gt;Collect XML - Windows Defender Logs, etc&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;These are just some examples and my personal views on which has richer field information.&lt;/P&gt;&lt;P&gt;You need to look at the EventViewer and decide which one has the right fields that you need.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!! Consider upvoting/accepting answer if this helped!!!&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 07:07:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/XML-Event-Viewer-Data-Missing-Message-Fields/m-p/596667#M48921</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-05-06T07:07:37Z</dc:date>
    </item>
  </channel>
</rss>

