Getting Data In

Clarification on WinEventLog vs wineventlog sourcetype?

TheBravoSierra
Path Finder

Hi all,

I have data coming in, parsing and indexing correctly to a windows index. This data comes in with either one of two sourcetypes: "WinEventLog" and "wineventlog".  The sources appear to be the same, so I am having difficulty understanding what corresponds to each sourcetype. Any help is appreciated. Thank you.

 

Labels (2)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@TheBravoSierra - Are you having Sysmon data? That may have "wineventlog" (lower case) sourcetype value.

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Since sourcetype is case-sensitive (regarding props.conf and event processing) so strictly technically these are two distinct sourcetypes. It seems though that for some reason (probably backwards compatibility) they share definitions in TA-windows.

Generally, you should be using the new name - WinEventLog.

0 Karma
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...