Getting Data In

Is it possible to index logs of memory.dmp in Splunk on Windows?

mrabbani
New Member

Can we take logs of memory.dmp into splunk in windows?
If yes.. how it is possible..
source (%systemRoot%\memory.dmp)

0 Karma

Ayn
Legend

No. The memory.dmp file is in a binary format that Splunk can't read. In order for Splunk to be able to read it, you'd need to convert whatever information you want into readable text and have Splunk read that.

0 Karma
Get Updates on the Splunk Community!

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...