Getting Data In

How to index .EVTX file stored in a different location on a universal forwarder?

bharathkumarnec
Contributor

HI All,

I would like to index .evtx file stored in a different location in my universal forwarder.

E:\Logs\Events\Fixed.Evtx

What are the approaches we have, to index these files?

I read some documentation but with few concerns, like it should not be written while read by splunk? if so, how can we achieve this?

Regards,
BK

0 Karma

tiagofbmm
Influencer

Splunk doesn't constantly lock a file so you don't have to worry about that.

Just put a monitor stanza over the file. (Imagine how splunk would be useless monitoring log files if it blocked it from being written at all times)

0 Karma

bharathkumarnec
Contributor

@tiagofbmm, Thanks for the details, did you try this anytime if so can i have the inputs how did it setup and what to consider in props & transforms on the indexer?

0 Karma

tiagofbmm
Influencer

Yes I dos monitor stanzas to files that are continuously being written and without a problem.

The props and transforms you may need or not will depend on what your file contains, which I am not aware of course.

Take a look at this doc for starters and explore from there if a simple monitor doesn't solve it

http://docs.splunk.com/Documentation/Splunk/7.0.2/Data/Monitorfilesanddirectorieswithinputs.conf

0 Karma

tiagofbmm
Influencer

Please let me know if the answer was useful for you. If it was, accept it and upvote. If not, give us more input so we can help you with that

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...