Splunk Search

rename wineventlog not happening for AWS generic s3

dhanasekar79
New Member

I have downloaded and installed the splunk TA for windows and splunk aws s3 in the search head and the universal forwarder. Created the generic s3 input to point to the S3 bucket storing the windows event logs.

When I run the search query in the indexer "sourcetype="WinEventLog", I am able to see the logs parsed by WinEventLog. However the renaming of the source to WinEventLog:Application seems to be not happening as I don't 'see the rename happening here.

Is there a way for me to troubleshoot this issue.

0 Karma

nickhills
Ultra Champion

How are the win event logs stored in s3?
Are you by chance trying to ingest .evtx files?

If my comment helps, please give it a thumbs up!
0 Karma

dhanasekar79
New Member

Win event logs are exported to S3 bucket from cloudwatch and stored in plain text format. in the aws generic s3 , the source type is set to "WinEventLog" and I see the logs are picked up. But it is not being transformed into "WinEventLog::Security", WinEventLog::Application as dictated in props.conf

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...