Getting Data In

How to parse the format of Windows Event Log, in order to forward these logs to syslog server?

leo_wang
Path Finder

Hi ,
For some reason , I must forward the Windows Event Log to our syslog server.
I configured the indexer server as document described, and it works successfully :
http://docs.splunk.com/Documentation/Splunk/6.5.1/Forwarding/Forwarddatatothird-partysystemsd
( The "Forward syslog data to a third-party host" part )

But I don't know how to parse the Windows Event Log that Splunk forwarded to me.
The attached screenshot is the example log I opened with "Sublime" ( Text Editor ).
alt text

It looks like Splunk converted the multi-line logs to single lines, and uses some special characters to format the log.
Anyone familiar with this format? How to parse it?

OR what does the character "NUL" exactly mean? and I notice there is a number ( usually 012 , 015 ) follow by this character , I guess they have special meanings ( like \t , \n ... or some control characters.)

0 Karma

jkat54
SplunkTrust
SplunkTrust

theres an option to sendCookedData in outputs.conf. You want to set that to false.

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...