Getting Data In

Monitoring Windows Hyper-V Event Logs

tgow
Splunk Employee
Splunk Employee

What is the inputs.conf syntax for monitoring Windows Hyper-V Event Logs? Hyper-V event logs are stored in the Event Viewer under "Applications and Services Logs", "Microsoft", "Windows".

Thanks in advance.

1 Solution

Ron_Naken
Splunk Employee
Splunk Employee

If you add a data input for either Local Event Log Collection or Remote Event Log Collection in the UI, Splunk will allow you to enumerate the log repositories under the various branches -- just click on the repository for Hyper-V to add it to the list.

The syntax for WMI.CONF looks like this for a remote machine:

[WMI:HyperV]
disabled = 0
event_log_file = <full name>
interval = 5
server = myserver

You can retrieve the <full name> of the log repository you want to index like this: open Microsoft Event Viewer, right-click the log repository for Hyper-V, click Properties, and copy/paste what's in the Full Name field.

HTH
Ron

View solution in original post

Ron_Naken
Splunk Employee
Splunk Employee

If you add a data input for either Local Event Log Collection or Remote Event Log Collection in the UI, Splunk will allow you to enumerate the log repositories under the various branches -- just click on the repository for Hyper-V to add it to the list.

The syntax for WMI.CONF looks like this for a remote machine:

[WMI:HyperV]
disabled = 0
event_log_file = <full name>
interval = 5
server = myserver

You can retrieve the <full name> of the log repository you want to index like this: open Microsoft Event Viewer, right-click the log repository for Hyper-V, click Properties, and copy/paste what's in the Full Name field.

HTH
Ron

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...