Dashboards & Visualizations

XML Event Viewer Data Missing Message\Fields

VTARNG_Paul
Explorer

Hi All,

I was hoping that modification of KV_Mode=xml in props.conf under the [xmlwineventlog] stanza on the standalone index\search head\deployment server would properly parse the Event View data from servers, but unfortunately I am not seeing all the message data that should be included. 

Here is sample of data, please see Event.EventData.Binary field:

VTARNG_Paul_0-1651750719929.png

 

Labels (1)
Tags (1)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@VTARNG_Paul - That's the problem with Windows I always face is that XML data (which is a new version) is not always a replica of PlainText (Legacy) format.

My views:

  • Collect PlainText - WinEventLog:Security, WinEventLog:System, etc
  • Collect XML - Windows Defender Logs, etc

These are just some examples and my personal views on which has richer field information.

You need to look at the EventViewer and decide which one has the right fields that you need.

 

I hope this helps!!! Consider upvoting/accepting answer if this helped!!!

View solution in original post

VatsalJagani
SplunkTrust
SplunkTrust

@VTARNG_Paul - Please look at the same event in Windows Event Viewer on the machine and see how you are seeing the fields and data.

Ideally, Splunk collects what is generated on the system.

0 Karma

VTARNG_Paul
Explorer

Hi,

From sourcetype XmlWinEventLog we are missing the data in these Event Viewer fields located in the General tab in this screenshot.  For example TaskCategory and Keywords.

It should be included as we are pulling the identical data from another server with sourcetype WinEventLog and all of those fields are in the events. 

VTARNG_Paul_0-1651770503624.png

 

Tags (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@VTARNG_Paul - Your Event Viewer should also show other sections as well for XML.

This screenshot is what PlainText formatted is what you can get in Splunk if you enable PlainText format event with inputs.conf.

0 Karma

VTARNG_Paul
Explorer

Hi,

You are correct the Message field is not included and other fields that I would like to use have generic names, Data, which is not very helpful for the reports/dashboard I want to make.

We are using xml because it requires less storage space and possibly faster, but have not really seen any performance advantage from my testing so far. 

I think we might have to rethink the xml version of that data.

VTARNG_Paul_0-1651775777525.png

 

Cheers, Paul

Tags (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@VTARNG_Paul - That's the problem with Windows I always face is that XML data (which is a new version) is not always a replica of PlainText (Legacy) format.

My views:

  • Collect PlainText - WinEventLog:Security, WinEventLog:System, etc
  • Collect XML - Windows Defender Logs, etc

These are just some examples and my personal views on which has richer field information.

You need to look at the EventViewer and decide which one has the right fields that you need.

 

I hope this helps!!! Consider upvoting/accepting answer if this helped!!!

richgalloway
SplunkTrust
SplunkTrust

The KV_Mode=xml setting will have no effect on that data since it is not in XML format.

Check the source application to see if there is a setting that will change the format to something non-binary.

---
If this reply helps you, Karma would be appreciated.
0 Karma

VTARNG_Paul
Explorer

Hi,

I am not seeing any non-binary setting for Event Viewer data.  

Thanks!

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...