Getting Data In

On a Linux Splunk Server, how do I ingest Windows CIFS audit files

rruth
Engager

I have adtlog.evt files I wish to look at from Splunk. How do I do this without using a Windows Splunk server? (I do have universal forwarders on some Windows systems if I need to go that route.) My Splunk server resides on Linux.

Details: I have a Netapp filer with CIFS mounts creating the adtlog.evt files and I want to use Splunk to search them.

0 Karma
1 Solution

rruth
Engager
0 Karma

Richfez
SplunkTrust
SplunkTrust

I don't think this will be easy. You could try something like evtviewer. Note I am not endorsing this, just suggesting it as a way to read those files. I have no idea how you would get that to export the files into a better format. To be honest, I'm not even sure Windows would have an easy way to do this.

Can you have it pick a different logging format? Does the control station (or whatever Netapp uses to "control" the filer) have a console you can get onto? Can you install software there? Does it have another log folder somewhere?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...