We have a customer that we are ingesting a number of windows event logs for ... we are using the pre-defined splunk source-type to ingest these.
We know that splunk captures the "Genera tabl" view details of the event, but our customer is asking if we can ingest the "Details tab" and under that there is a XML view. He is wanting to be able to search on a ID that shows up in the xml that unfortunately does not show in the "General tab" view.
Is splunk able to ingest that xml somehow?
Thanks for the help.
I'm able to ingest the XML version of these events just fine. I seem to be having issues with line breaking. I can't seem to nail down the stanza line that will accurately display the data in a readable format. Anyone have a suggestion for the props.conf to achieve this? Thanks.
Hmmm. Are you in fact using the sourcetype already provided in the TAs referenced here? If so and still having problems it might be stronger to start a new question (feel free to cross reference this one) and provide greater detail.
You can just add that line and it will change formats. It does not work for Windows (server?) 2003 and has some other caveats so I would read ALL the documentation pages on it.