Getting Data In

Local Windows Event [WinEventLog://Application]

steveo2
Engager

Hi! I'm trying to collect the local splunk server Windows Application event logs.   I would like them in non_XML format.  In .../app/Splunk_TA_windows/inputs.conf stanza I added:   

[WinEventLog://Application]
index = splunk_server_app
source = WinEventLog:Application
sourcetype = WinEventLog
disabled = 0
renderXML = 0

I'm getting events but they are in XML format.  Using Splunk Enterprise version 8.1.4.

Any help wond be appreciated.  Thanks

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...