<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Getting Data into Splunk in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Getting-Data-into-Splunk/m-p/551254#M156427</link>
    <description>&lt;P&gt;I just installed splunk and imported my license.&lt;/P&gt;&lt;P&gt;I have a series of Windows event viewer files that have been exported that I want to import.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried the following:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Settings --&amp;gt; Add Data&lt;/LI&gt;&lt;LI&gt;Upload Files From My computer&lt;/LI&gt;&lt;LI&gt;Select the file.&amp;nbsp; It reads the file.&lt;/LI&gt;&lt;LI&gt;Next&lt;/LI&gt;&lt;LI&gt;Select Preprocess-winevt&lt;/LI&gt;&lt;LI&gt;Next&lt;/LI&gt;&lt;LI&gt;Review&lt;/LI&gt;&lt;LI&gt;Submit&lt;/LI&gt;&lt;LI&gt;Start Searching&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;No events are shown.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I doing wrong?&lt;/P&gt;</description>
    <pubDate>Tue, 11 May 2021 15:22:12 GMT</pubDate>
    <dc:creator>rockb</dc:creator>
    <dc:date>2021-05-11T15:22:12Z</dc:date>
    <item>
      <title>Getting Data into Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-Data-into-Splunk/m-p/551254#M156427</link>
      <description>&lt;P&gt;I just installed splunk and imported my license.&lt;/P&gt;&lt;P&gt;I have a series of Windows event viewer files that have been exported that I want to import.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried the following:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Settings --&amp;gt; Add Data&lt;/LI&gt;&lt;LI&gt;Upload Files From My computer&lt;/LI&gt;&lt;LI&gt;Select the file.&amp;nbsp; It reads the file.&lt;/LI&gt;&lt;LI&gt;Next&lt;/LI&gt;&lt;LI&gt;Select Preprocess-winevt&lt;/LI&gt;&lt;LI&gt;Next&lt;/LI&gt;&lt;LI&gt;Review&lt;/LI&gt;&lt;LI&gt;Submit&lt;/LI&gt;&lt;LI&gt;Start Searching&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;No events are shown.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I doing wrong?&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 15:22:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-Data-into-Splunk/m-p/551254#M156427</guid>
      <dc:creator>rockb</dc:creator>
      <dc:date>2021-05-11T15:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data into Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-Data-into-Splunk/m-p/551255#M156428</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234313"&gt;@rockb&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope checked in all time range and playing with search&amp;nbsp;also.&lt;/P&gt;&lt;P&gt;Just guessing the reason and I doubt on retention period of Index. Just check the possible _time of indexed event and index retention period.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 15:32:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-Data-into-Splunk/m-p/551255#M156428</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-05-11T15:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data into Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-Data-into-Splunk/m-p/551257#M156429</link>
      <description>&lt;P&gt;&lt;SPAN&gt;kamlesh,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I think you are saying to make sure that I am specifying to show all events not just events in a specific time period.&amp;nbsp; I did not select any time period and if I understand the interface correctly it is saying it sees no events prior to today at 10:52&amp;nbsp; There are 8198 events listed when I open the evtx file in Windows event viewer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rockb_0-1620748411960.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14115iF9BE9482066B31B8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rockb_0-1620748411960.png" alt="rockb_0-1620748411960.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 15:55:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-Data-into-Splunk/m-p/551257#M156429</guid>
      <dc:creator>rockb</dc:creator>
      <dc:date>2021-05-11T15:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data into Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-Data-into-Splunk/m-p/551380#M156469</link>
      <description>&lt;P&gt;I figured it out.&amp;nbsp; After the process is complete the Search window has host="xxxx" and sourcetype="preprocess-winevt".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I delete host="xxxx" and sourcetype="preprocess-winevt". events are shown.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 17:13:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-Data-into-Splunk/m-p/551380#M156469</guid>
      <dc:creator>rockb</dc:creator>
      <dc:date>2021-05-12T17:13:28Z</dc:date>
    </item>
  </channel>
</rss>

