Dashboards & Visualizations

file modified during boot not indexed

wieljer
Engager

Hi Everyone,

I have a problem with Splunk not indexing an XML file, modified during the windows boot process. Windows 10 creates an encrypted file during bootup which our powershell script parses and places the result in a location "c:\tpm" using a windows startup script.

What I've tried
- I added MAX_EVENTS to the props.conf and also on the sourcetype on the indexer for 100,000 lines because it is larger than the default limit.
- If I open the xml file manually and add something into it, Splunk will pickup those changes.

Since the file is not indexed without being modified while the SUF is running, I figured a setting might be needed. Any ideas?

Thanks,
wieljer

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What are the current inputs.conf settings for the file?

---
If this reply helps you, Karma would be appreciated.
0 Karma

wieljer
Engager

Hey thanks for the inquiry
[monitor://C:\TPM]
disabled = false
followTail = 0
sourcetype = winTPM
index = win10

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...