Archive

Windows app and Windows 2008 evtx logs

Engager

Does the windows app work with 2008 event log files? Is the Windows app the best way to monitor windows logs?

Tags (1)
0 Karma

Splunk Employee
Splunk Employee

The Windows app is the best way to monitor Windows Event Logs, but it doesn't monitor the evtx files. (The files are [or can be] created by the Event Logging system, but the Splunk WinEventLog monitor talks directly to the Event Logging system rather than looking.)

Engager

So then what is the recommended method for ingesting evtx files from Windows 2008? Also, when I enable and configure the Windows App to monitor my event logs, on both 2003 and 2008 servers, nothing is getting ingested. I verified that my account has full control over the Splunk installation directory. I am now manually entering the Windows stanzas in the inputs.conf file....

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!