Getting Data In

How to parse the format of Windows Event Log, in order to forward these logs to syslog server?

leo_wang
Path Finder

Hi ,
For some reason , I must forward the Windows Event Log to our syslog server.
I configured the indexer server as document described, and it works successfully :
http://docs.splunk.com/Documentation/Splunk/6.5.1/Forwarding/Forwarddatatothird-partysystemsd
( The "Forward syslog data to a third-party host" part )

But I don't know how to parse the Windows Event Log that Splunk forwarded to me.
The attached screenshot is the example log I opened with "Sublime" ( Text Editor ).
alt text

It looks like Splunk converted the multi-line logs to single lines, and uses some special characters to format the log.
Anyone familiar with this format? How to parse it?

OR what does the character "NUL" exactly mean? and I notice there is a number ( usually 012 , 015 ) follow by this character , I guess they have special meanings ( like \t , \n ... or some control characters.)

0 Karma

jkat54
SplunkTrust
SplunkTrust

theres an option to sendCookedData in outputs.conf. You want to set that to false.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...