Getting Data In

Can Splunk ingest the "Details tab - xml view" of a Windows Event Log?

a548506
Path Finder

Hello All,

We have a customer that we are ingesting a number of windows event logs for ... we are using the pre-defined splunk source-type to ingest these.

We know that splunk captures the "Genera tabl" view details of the event, but our customer is asking if we can ingest the "Details tab" and under that there is a XML view. He is wanting to be able to search on a ID that shows up in the xml that unfortunately does not show in the "General tab" view.

Is splunk able to ingest that xml somehow?

Thanks for the help.

0 Karma
1 Solution

nthornbury
Explorer

I'm able to ingest the XML version of these events just fine. I seem to be having issues with line breaking. I can't seem to nail down the stanza line that will accurately display the data in a readable format. Anyone have a suggestion for the props.conf to achieve this? Thanks.

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Hmmm. Are you in fact using the sourcetype already provided in the TAs referenced here? If so and still having problems it might be stronger to start a new question (feel free to cross reference this one) and provide greater detail.

0 Karma

a548506
Path Finder

@woodcock,

Would I need to download this Splunk_TA_Windows app? Can't tell if i do or it's just as simple as adding that line in my inputs.conf.

Thanks again.

0 Karma

woodcock
Esteemed Legend

You can just add that line and it will change formats. It does not work for Windows (server?) 2003 and has some other caveats so I would read ALL the documentation pages on it.

0 Karma

a548506
Path Finder

@woodcock,

Thanks for the help, it worked. Another question ... is this xml data getting indexed as well? Meaning are we getting "double charged" ?

Thanks again

0 Karma

sloshburch
Splunk Employee
Splunk Employee

@woodcock - you missed a great opportunity to do the Socratic Method on @a548506 😉

@a548506 - How might you check for the answer to your question about licensing? Can you think of any particular dashboards, searches, datasources, etc.. that would facilitate this? Hint

0 Karma

woodcock
Esteemed Legend

The XML is your new data exactly as you see it. The original event format is fully replaced so you are not getting "double".

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...