Getting Data In

How to index .EVTX file stored in a different location on a universal forwarder?

bharathkumarnec
Contributor

HI All,

I would like to index .evtx file stored in a different location in my universal forwarder.

E:\Logs\Events\Fixed.Evtx

What are the approaches we have, to index these files?

I read some documentation but with few concerns, like it should not be written while read by splunk? if so, how can we achieve this?

Regards,
BK

0 Karma

tiagofbmm
Influencer

Splunk doesn't constantly lock a file so you don't have to worry about that.

Just put a monitor stanza over the file. (Imagine how splunk would be useless monitoring log files if it blocked it from being written at all times)

0 Karma

bharathkumarnec
Contributor

@tiagofbmm, Thanks for the details, did you try this anytime if so can i have the inputs how did it setup and what to consider in props & transforms on the indexer?

0 Karma

tiagofbmm
Influencer

Yes I dos monitor stanzas to files that are continuously being written and without a problem.

The props and transforms you may need or not will depend on what your file contains, which I am not aware of course.

Take a look at this doc for starters and explore from there if a simple monitor doesn't solve it

http://docs.splunk.com/Documentation/Splunk/7.0.2/Data/Monitorfilesanddirectorieswithinputs.conf

0 Karma

tiagofbmm
Influencer

Please let me know if the answer was useful for you. If it was, accept it and upvote. If not, give us more input so we can help you with that

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...