Getting Data In

Is it possible to index logs of memory.dmp in Splunk on Windows?

mrabbani
New Member

Can we take logs of memory.dmp into splunk in windows?
If yes.. how it is possible..
source (%systemRoot%\memory.dmp)

0 Karma

Ayn
Legend

No. The memory.dmp file is in a binary format that Splunk can't read. In order for Splunk to be able to read it, you'd need to convert whatever information you want into readable text and have Splunk read that.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!