<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to import Windows Log files? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-import-Windows-Log-files/m-p/29393#M177936</link>
    <description>&lt;P&gt;Just to start...did you read &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/MonitorWindowsdata"&gt;Monitor Windows event log data&lt;/A&gt; in the Getting Data In Manual? &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/ConsiderationsfordecidinghowtomonitorWindowsdata"&gt;Considerations for deciding how to monitor remote Windows data&lt;/A&gt; is worth looking at as well if you have a significant number of Windows hosts.&lt;/P&gt;</description>
    <pubDate>Fri, 09 Nov 2012 18:35:07 GMT</pubDate>
    <dc:creator>ChrisG</dc:creator>
    <dc:date>2012-11-09T18:35:07Z</dc:date>
    <item>
      <title>How to import Windows Log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-import-Windows-Log-files/m-p/29392#M177935</link>
      <description>&lt;P&gt;I'm a new Splunk user so don't dump on me if theis is a dumb quesiton but I can't find any tutorials or how to for Splunk 5.&lt;/P&gt;

&lt;P&gt;I have an Microsoft evt and evtx files.  (Microsoft log files.)  Downloaded and installed Splunk 5, so default install.  When I attempt to import the evt and evtx files all I see is what appears to be junk in the preview window.&lt;/P&gt;

&lt;P&gt;In looking at instructions for previous versions of Splunk it appears there's an add-in or modules I need to add Microsoft event files.  Do I need to do the same with Splunk 5?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2012 18:13:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-import-Windows-Log-files/m-p/29392#M177935</guid>
      <dc:creator>Douggg</dc:creator>
      <dc:date>2012-11-09T18:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to import Windows Log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-import-Windows-Log-files/m-p/29393#M177936</link>
      <description>&lt;P&gt;Just to start...did you read &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/MonitorWindowsdata"&gt;Monitor Windows event log data&lt;/A&gt; in the Getting Data In Manual? &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/ConsiderationsfordecidinghowtomonitorWindowsdata"&gt;Considerations for deciding how to monitor remote Windows data&lt;/A&gt; is worth looking at as well if you have a significant number of Windows hosts.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2012 18:35:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-import-Windows-Log-files/m-p/29393#M177936</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2012-11-09T18:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to import Windows Log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-import-Windows-Log-files/m-p/29394#M177937</link>
      <description>&lt;P&gt;The issue is that evt/evtx files are binary and can't be imported natively to Splunk.&lt;/P&gt;

&lt;P&gt;You can install &lt;A href="http://splunk-base.splunk.com/apps/22315/splunk-app-for-windows"&gt;Splunk for Windows&lt;/A&gt; if you are using a full Splunk installation and that will allow some support for indexing the events from event viewer. Or if you have the universal forwarder installed you can configure windows &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Admin/Inputsconf"&gt;scripted inputs&lt;/A&gt; to capture events from the events viewer and forward them to Splunk.&lt;/P&gt;

&lt;P&gt;-kate&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2012 18:39:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-import-Windows-Log-files/m-p/29394#M177937</guid>
      <dc:creator>Kate_Lawrence-G</dc:creator>
      <dc:date>2012-11-09T18:39:31Z</dc:date>
    </item>
  </channel>
</rss>

