All Apps and Add-ons

Indexing exported .evtx files in XML format (NetApp file audit logs)

ikulcsar
Communicator

Hi,

I have to index exported .evxt files on a Windows box. I can process these evtx files with Splunk and events looks likes as in Windows Event viewer's "General" tabs shows it. Unfortunately, because of the structure of the event, I need the events in the format as the "Detailed" tab show them.

So the question: how can I index evtx files in "Detailed" (XML) format? So far renderXml stanza doesn't help me. Currently I user simple Monitor stanza to monitor the directory of the evtx files.

To be more specific: these are NetApp-Security-Audit files, about events accessing shared files. How should I handle this files, does anyone has (good) experience whit them?

Regards,
István

Tags (2)
0 Karma

mhoogcarspel_sp
Splunk Employee
Splunk Employee

Maarten from support here, I found this after the case you raised with me.

I provided something similar to the answer here:
https://answers.splunk.com/answers/386482/how-to-configure-splunk-to-index-netapp-cifs-logs.html

[netapp-audit]
SHOULD_LINEMERGE=false
LINE_BREAKER=()()
TIME_PREFIX=TimeCreated
KV_MODE=xml

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...