Getting Data In

Local Windows Event [WinEventLog://Application]

steveo2
Engager

Hi! I'm trying to collect the local splunk server Windows Application event logs.   I would like them in non_XML format.  In .../app/Splunk_TA_windows/inputs.conf stanza I added:   

[WinEventLog://Application]
index = splunk_server_app
source = WinEventLog:Application
sourcetype = WinEventLog
disabled = 0
renderXML = 0

I'm getting events but they are in XML format.  Using Splunk Enterprise version 8.1.4.

Any help wond be appreciated.  Thanks

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...