Getting Data In

Local Windows Event [WinEventLog://Application]

steveo2
Engager

Hi! I'm trying to collect the local splunk server Windows Application event logs.   I would like them in non_XML format.  In .../app/Splunk_TA_windows/inputs.conf stanza I added:   

[WinEventLog://Application]
index = splunk_server_app
source = WinEventLog:Application
sourcetype = WinEventLog
disabled = 0
renderXML = 0

I'm getting events but they are in XML format.  Using Splunk Enterprise version 8.1.4.

Any help wond be appreciated.  Thanks

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Exciting News: The AppDynamics Community Joins Splunk!

Hello Splunkers,   I’d like to introduce myself—I’m Ryan, the former AppDynamics Community Manager, and I’m ...

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...