All Apps and Add-ons

Indexing exported .evtx files in XML format (NetApp file audit logs)

ikulcsar
Communicator

Hi,

I have to index exported .evxt files on a Windows box. I can process these evtx files with Splunk and events looks likes as in Windows Event viewer's "General" tabs shows it. Unfortunately, because of the structure of the event, I need the events in the format as the "Detailed" tab show them.

So the question: how can I index evtx files in "Detailed" (XML) format? So far renderXml stanza doesn't help me. Currently I user simple Monitor stanza to monitor the directory of the evtx files.

To be more specific: these are NetApp-Security-Audit files, about events accessing shared files. How should I handle this files, does anyone has (good) experience whit them?

Regards,
István

Tags (2)
0 Karma

mhoogcarspel_sp
Splunk Employee
Splunk Employee

Maarten from support here, I found this after the case you raised with me.

I provided something similar to the answer here:
https://answers.splunk.com/answers/386482/how-to-configure-splunk-to-index-netapp-cifs-logs.html

[netapp-audit]
SHOULD_LINEMERGE=false
LINE_BREAKER=()()
TIME_PREFIX=TimeCreated
KV_MODE=xml

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...