Getting Data In

On a Linux Splunk Server, how do I ingest Windows CIFS audit files

rruth
Engager

I have adtlog.evt files I wish to look at from Splunk. How do I do this without using a Windows Splunk server? (I do have universal forwarders on some Windows systems if I need to go that route.) My Splunk server resides on Linux.

Details: I have a Netapp filer with CIFS mounts creating the adtlog.evt files and I want to use Splunk to search them.

0 Karma
1 Solution

rruth
Engager
0 Karma

Richfez
SplunkTrust
SplunkTrust

I don't think this will be easy. You could try something like evtviewer. Note I am not endorsing this, just suggesting it as a way to read those files. I have no idea how you would get that to export the files into a better format. To be honest, I'm not even sure Windows would have an easy way to do this.

Can you have it pick a different logging format? Does the control station (or whatever Netapp uses to "control" the filer) have a console you can get onto? Can you install software there? Does it have another log folder somewhere?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...