<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to send Windows log to Splunk? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609326#M211886</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I changed the full stanza and used the local folder input.conf entries just the wineventlog:security stanza, enabling it.&lt;BR /&gt;but still not showing any srcip and port, ip address&lt;BR /&gt;&lt;BR /&gt;Maybe splunk running locally and getting a local event log, meaning it doesn't show any ip address and port or srcip sections in the eventog?&lt;/P&gt;</description>
    <pubDate>Fri, 12 Aug 2022 13:26:17 GMT</pubDate>
    <dc:creator>rockzers</dc:creator>
    <dc:date>2022-08-12T13:26:17Z</dc:date>
    <item>
      <title>How to send Windows log to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609110#M211796</link>
      <description>&lt;P&gt;new splunk user&lt;/P&gt;&lt;P&gt;i installed my splunk on my windows machine and i want to receive logs and how to find a logon event?&lt;/P&gt;&lt;P&gt;in the search index there is only default index=internal and audit, so these logs are the same received login event logs?. Is it detected logon event if the user accesses this windows machine?&lt;/P&gt;&lt;P&gt;Do I need to install any third party application to get logs? because splunk forwarder is a remote way to send logs so on local machine how can i do that?&lt;/P&gt;&lt;P&gt;i want to check user login event in splunk&lt;/P&gt;&lt;P&gt;Example:&lt;BR /&gt;if user access this windows machine then SIEM splunk job is check logon event log details like if people with valid IP only access this windows machine or not&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 04:18:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609110#M211796</guid>
      <dc:creator>rockzers</dc:creator>
      <dc:date>2022-08-11T04:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to send Windows log to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609112#M211797</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248395"&gt;@rockzers&lt;/a&gt;&amp;nbsp;you might need to install this add-on and enable required inputs, follow the instructions -&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Windows/AbouttheSplunkAdd-onforWindows" target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/released/Windows/AbouttheSplunkAdd-onforWindows&lt;/A&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;Srikanth Yarlagadda&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 04:58:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609112#M211797</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2022-08-11T04:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to send Windows log to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609121#M211802</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248395"&gt;@rockzers&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I hint to follow some basic training on Splunk:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;getting started with search (&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Search/GetstartedwithSearch" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Search/GetstartedwithSearch&lt;/A&gt;)&lt;/LI&gt;&lt;LI&gt;Splunk Search Tutorial (&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial&lt;/A&gt;)&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;to be authonomous in your activities.&lt;/P&gt;&lt;P&gt;Anyway, do you want to take logs from your local machine or from another one?&lt;/P&gt;&lt;P&gt;If from your local machine, you can go in [Settings -- inputs] and find how to enable local windows eventlogs.&lt;/P&gt;&lt;P&gt;If from another machine, is just a little bit complicate (not so much) you have to install:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Splunk Enterprise on your Splunk machine,&lt;/LI&gt;&lt;LI&gt;Splunk Universal Forwarder on the target machine,&lt;/LI&gt;&lt;LI&gt;Splunk_TA_Windows (&lt;A href="https://splunkbase.splunk.com/app/742/" target="_blank"&gt;https://splunkbase.splunk.com/app/742/&lt;/A&gt;) on your target machine and on your Splunk machine.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Then configure your target machine to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;send logs to your Splunk machine,&lt;/LI&gt;&lt;LI&gt;enable inputs on the target machine in the Splunk_TA_Windows inputs.conf.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;When you'll have logs in your Splunk machine, you can create your searches (as you learned in Splunk Search Tutorial).&lt;/P&gt;&lt;P&gt;To list all the logon events, you could run something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=wineventlog EventCode=4624&lt;/LI-CODE&gt;&lt;P&gt;Remember that every logon in Windows generated around 12-13 logon events, so you have to analyze and filter them.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 06:44:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609121#M211802</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-11T06:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to send Windows log to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609142#M211811</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;thanks for your suggestion&amp;nbsp;&lt;/P&gt;&lt;P&gt;I installed Splunk_TA_Windows and created it in the local input.config folder&lt;/P&gt;&lt;P&gt;Which one is get login event to enable in input.config ?&lt;BR /&gt;&lt;BR /&gt;because input.config there are many events so i just need login event log to receive in splunk&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 10:41:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609142#M211811</guid>
      <dc:creator>rockzers</dc:creator>
      <dc:date>2022-08-11T10:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to send Windows log to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609179#M211828</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248395"&gt;@rockzers&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the stanza is winevenlog:security, usually the first.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 13:23:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609179#M211828</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-11T13:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to send Windows log to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609229#M211845</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Should I remove the other log all settings in input.config and just use the WinEventLog://security logs to check the login event in Splunk?&lt;BR /&gt;&lt;BR /&gt;because i checked and used only security in eventlog input.config and it received logs but when i check the logs it doesn't show my src and src port or ip address is empty&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 03:03:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609229#M211845</guid>
      <dc:creator>rockzers</dc:creator>
      <dc:date>2022-08-12T03:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to send Windows log to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609232#M211848</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163730"&gt;@venkatasri&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;i installed it and i just need the login event log&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 03:06:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609232#M211848</guid>
      <dc:creator>rockzers</dc:creator>
      <dc:date>2022-08-12T03:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to send Windows log to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609254#M211859</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248395"&gt;@rockzers&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;usually the approach is to leave in default folder the complete inputs.conf as is, with all the disabled stanzas, and then copy in local folder's inputs.conf only the wineventlog:security stanza, enabling it.&lt;/P&gt;&lt;P&gt;You could also insert in this inputs.conf only the stanza's header and the option "disabled=0", but I prefer to copy the full stanza.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 06:55:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609254#M211859</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-12T06:55:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to send Windows log to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609326#M211886</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I changed the full stanza and used the local folder input.conf entries just the wineventlog:security stanza, enabling it.&lt;BR /&gt;but still not showing any srcip and port, ip address&lt;BR /&gt;&lt;BR /&gt;Maybe splunk running locally and getting a local event log, meaning it doesn't show any ip address and port or srcip sections in the eventog?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 13:26:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609326#M211886</guid>
      <dc:creator>rockzers</dc:creator>
      <dc:date>2022-08-12T13:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to send Windows log to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609418#M211915</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248395"&gt;@rockzers&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Aug 2022 10:12:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-send-Windows-log-to-Splunk/m-p/609418#M211915</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-14T10:12:44Z</dc:date>
    </item>
  </channel>
</rss>

