Getting Data In

How can I reindex a [WinEventLog://___] file with Splunk_TA_windows?

andrewaalin
Explorer

crcSalt does not work with this type of input.
If this were not binary data, I would do some text substitution with sed, but I don't know of a way to do that with binary evtx.

0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

WinEventLog is a modular input, it does not monitor files, but query the windows Winevent endpoint.
Splunk uses a checkpoint to identify the latest event id collected per channel.

If you want to reindex a channel, you can reset the checkpoint.
1- stop splunk
2 - Look on the forwarder in a folder like $SPLUNK_HOME\var\lib\splunk\modinputs\wineventlogs
and in side the folder you will find a file (xml format) for each channel (security, applications etc..)
3- remove the file
4- restart splunk
it should cause the forwarder to forget the last checkpoints, and restart from the beginning.
warning : It may cause duplicates, as it will resend them all, and it may take some time to backfill all the events, if they are several month of old data.

View solution in original post

yannK
Splunk Employee
Splunk Employee

WinEventLog is a modular input, it does not monitor files, but query the windows Winevent endpoint.
Splunk uses a checkpoint to identify the latest event id collected per channel.

If you want to reindex a channel, you can reset the checkpoint.
1- stop splunk
2 - Look on the forwarder in a folder like $SPLUNK_HOME\var\lib\splunk\modinputs\wineventlogs
and in side the folder you will find a file (xml format) for each channel (security, applications etc..)
3- remove the file
4- restart splunk
it should cause the forwarder to forget the last checkpoints, and restart from the beginning.
warning : It may cause duplicates, as it will resend them all, and it may take some time to backfill all the events, if they are several month of old data.

andrewaalin
Explorer

Thanks, trying this out now.

0 Karma

andrewaalin
Explorer

That worked, thanks!

0 Karma

yannK
Splunk Employee
Splunk Employee

alt text

somesoni2
Revered Legend

Are you monitoring any other files from the forwarder where you want to collect WinEventLogs?

0 Karma

andrewaalin
Explorer

Yes, although this is a Dev environment so I don't mind if those are disrupted.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...