Getting Data In

How to configure inputs.conf to get PowerShell and WinRM event logs from Windows hosts?

pkeller
Contributor

I've been asked to index both Operational.evtx and Analytic.etl from both \Winevt\Logs\Microsoft-Windows-WinRM and \Winevt\Logs\Microsoft-Windows-PowerShell from a few Windows hosts.

I'm not quite sure how to configure the inputs.conf for this. I'm guessing that it's something like:

[WinEventLog:PowerShell]
disabled = 1
start_from = oldest
current_only = 0
evt_resolve_ad_obj = 1
checkpointInterval = 5
renderXml=false
or

[WinEventLog:WinRM]
..

But again, not really clear. (and not at all Windows literate) And then how do you differentiate between the Operational and Analytic objects.

Thank you

0 Karma

ddrillic
Ultra Champion

The following speaks about it - Forwarding Windows Event Logs to another host

In Step 4, it shows -

[WinEventLog://SOURCE-Security]
sourcetype = WinEventLog:Security
host = SOURCE
disabled = false
0 Karma

spayneort
Contributor
[WinEventLog://Microsoft-Windows-PowerShell/Operational]
disabled = false

[WinEventLog://Microsoft-Windows-WinRM/Operational]
disabled = false
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...