Getting Data In

Stanza for to ingest logs from specific date

phanichintha
Path Finder

Hello Team,

I want the stanza to ingest logs from a specific date in Linux or Window environment.

Currently am using windows (ignoreOlderThan = 365d) and the same using for Linux it's not working.

Requirement: I want to ingest logs from Linux via UF and windows machines to Splunk, so I want only 356days or 180days. Can anyone share other than the above stanza?

Example:

 [WinEventLog://Security]
disabled = 0
index = trendmicro
sourcetype = %trendmicro%
ignoreOlderThan = 365d
whitelist = 4625,4648,4723,4728,4732,4740,4777,5031,4624,4634

 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The ignoreOlderThan setting is for monitor inputs, not WinEventLog.  I'm not aware of a setting that controls how far back into the event log the forwarder will read.

---
If this reply helps you, Karma would be appreciated.
0 Karma

phanichintha
Path Finder

Hello Rich,

If that is not the case, can you please which stanza can I use for my question?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

As I said in my original answer, I'm not aware of ANY settings that do what you want.

However, ingestion of older events is a one-time happening so why not just let it happen?  

---
If this reply helps you, Karma would be appreciated.
0 Karma

phanichintha
Path Finder

please suggest some stanzas to find out the way.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...