All Apps and Add-ons

Indexing exported .evtx files in XML format (NetApp file audit logs)

ikulcsar
Communicator

Hi,

I have to index exported .evxt files on a Windows box. I can process these evtx files with Splunk and events looks likes as in Windows Event viewer's "General" tabs shows it. Unfortunately, because of the structure of the event, I need the events in the format as the "Detailed" tab show them.

So the question: how can I index evtx files in "Detailed" (XML) format? So far renderXml stanza doesn't help me. Currently I user simple Monitor stanza to monitor the directory of the evtx files.

To be more specific: these are NetApp-Security-Audit files, about events accessing shared files. How should I handle this files, does anyone has (good) experience whit them?

Regards,
István

Tags (2)
0 Karma

mhoogcarspel_sp
Splunk Employee
Splunk Employee

Maarten from support here, I found this after the case you raised with me.

I provided something similar to the answer here:
https://answers.splunk.com/answers/386482/how-to-configure-splunk-to-index-netapp-cifs-logs.html

[netapp-audit]
SHOULD_LINEMERGE=false
LINE_BREAKER=()()
TIME_PREFIX=TimeCreated
KV_MODE=xml

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...