Getting Data In

On a Linux Splunk Server, how do I ingest Windows CIFS audit files

rruth
Engager

I have adtlog.evt files I wish to look at from Splunk. How do I do this without using a Windows Splunk server? (I do have universal forwarders on some Windows systems if I need to go that route.) My Splunk server resides on Linux.

Details: I have a Netapp filer with CIFS mounts creating the adtlog.evt files and I want to use Splunk to search them.

0 Karma
1 Solution

rruth
Engager
0 Karma

Richfez
SplunkTrust
SplunkTrust

I don't think this will be easy. You could try something like evtviewer. Note I am not endorsing this, just suggesting it as a way to read those files. I have no idea how you would get that to export the files into a better format. To be honest, I'm not even sure Windows would have an easy way to do this.

Can you have it pick a different logging format? Does the control station (or whatever Netapp uses to "control" the filer) have a console you can get onto? Can you install software there? Does it have another log folder somewhere?

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...