<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WinEventLog - Appliction and Services Logs in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/WinEventLog-Appliction-and-Services-Logs-Does-anyone-have-a-doc/m-p/599501#M208675</link>
    <description>&lt;P&gt;The syntax for Windows event log stanza is:&lt;BR /&gt;&lt;BR /&gt;[WinEventLog://&amp;lt;channel-name&amp;gt;]&lt;/P&gt;</description>
    <pubDate>Thu, 26 May 2022 20:35:42 GMT</pubDate>
    <dc:creator>wcolgate_splunk</dc:creator>
    <dc:date>2022-05-26T20:35:42Z</dc:date>
    <item>
      <title>WinEventLog - Appliction and Services Logs- Does anyone have a doc or suggestion?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WinEventLog-Appliction-and-Services-Logs-Does-anyone-have-a-doc/m-p/514138#M144303</link>
      <description>&lt;P&gt;Trying to collect information from a sub folder in a Windows server event log. Specifically in the Applications and Services Logs/DFS Replication folder. So far it looks like I need to add some info to my local conf file, but unsure of the proper syntax. I believe it would be along these lines:&lt;/P&gt;
&lt;P&gt;[WinEventLog:"Application and Services Logs/DFSReplication"]&lt;BR /&gt;disabled=0&lt;BR /&gt;start from=oldest&lt;BR /&gt;currentonly=0&lt;/P&gt;
&lt;P&gt;Can anyone point me to the proper doc to figure this out or offer a suggestion. Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2022 20:38:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WinEventLog-Appliction-and-Services-Logs-Does-anyone-have-a-doc/m-p/514138#M144303</guid>
      <dc:creator>ttiller</dc:creator>
      <dc:date>2022-05-26T20:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog - Appliction and Services Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WinEventLog-Appliction-and-Services-Logs-Does-anyone-have-a-doc/m-p/514140#M144304</link>
      <description>Have you tried removing the quotation marks from the stanza name?</description>
      <pubDate>Fri, 14 Aug 2020 15:11:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WinEventLog-Appliction-and-Services-Logs-Does-anyone-have-a-doc/m-p/514140#M144304</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-14T15:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog - Appliction and Services Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WinEventLog-Appliction-and-Services-Logs-Does-anyone-have-a-doc/m-p/514144#M144306</link>
      <description>&lt;P&gt;I have not. I was unsure if I was even on the right track and did not want to jump off the cliff without some assurances that I'm not going to screw something up. "Nothing ventured nothing gained" as they say. Will give it a go and let you know. Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 15:17:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WinEventLog-Appliction-and-Services-Logs-Does-anyone-have-a-doc/m-p/514144#M144306</guid>
      <dc:creator>ttiller</dc:creator>
      <dc:date>2020-08-14T15:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog - Appliction and Services Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WinEventLog-Appliction-and-Services-Logs-Does-anyone-have-a-doc/m-p/517090#M145367</link>
      <description>&lt;P&gt;The adjustment was&amp;nbsp; made on the backend so now my search should be successful. Thank you for your suggestion.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 18:45:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WinEventLog-Appliction-and-Services-Logs-Does-anyone-have-a-doc/m-p/517090#M145367</guid>
      <dc:creator>ttiller</dc:creator>
      <dc:date>2020-08-31T18:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog - Appliction and Services Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WinEventLog-Appliction-and-Services-Logs-Does-anyone-have-a-doc/m-p/517121#M145382</link>
      <description>&lt;P&gt;If your problem is resolved, then please click the "Accept as Solution" button to help future readers.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 20:58:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WinEventLog-Appliction-and-Services-Logs-Does-anyone-have-a-doc/m-p/517121#M145382</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-31T20:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog - Appliction and Services Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WinEventLog-Appliction-and-Services-Logs-Does-anyone-have-a-doc/m-p/599501#M208675</link>
      <description>&lt;P&gt;The syntax for Windows event log stanza is:&lt;BR /&gt;&lt;BR /&gt;[WinEventLog://&amp;lt;channel-name&amp;gt;]&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2022 20:35:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WinEventLog-Appliction-and-Services-Logs-Does-anyone-have-a-doc/m-p/599501#M208675</guid>
      <dc:creator>wcolgate_splunk</dc:creator>
      <dc:date>2022-05-26T20:35:42Z</dc:date>
    </item>
  </channel>
</rss>

