Getting Data In

What is the best practice for data structure of Wineventlog?

anandhalagarasa
Path Finder

We are ingesting wineventlog into Splunk Cloud from all our client servers.
And the majority of the ingested data seems to be in XML format and few hosts are reporting with normal log structure.

So I want to know whether we can ingest the data in XML format itself or can I modify it to the normal structure by adding some stanza in the input .conf file of the wineventlog app.

Which one would be considered as a best practice and a recommended one as well?

0 Karma

jacobpevans
Motivator

Greetings @anandhalagarasan,

The inputs.conf command you are looking for is:

renderXML = false or
renderXML = true under a stanza similar to this:

[WinEventLog://Application] or
[WinEventLog://Security], etc.

See more information here: https://docs.splunk.com/Documentation/WindowsAddOn/latest/User/Configuration

I can't comment on best practice. It's up to you and your environment as to which one works better for you - the important thing is to be consistent (ideally using a deployment server). We do not render XML since most of our users are more familiar with the standard way Windows displays Windows Events.

Cheers,
Jacob

If you feel this response answered your question, please do not forget to mark it as such. If it did not, but you do have the answer, feel free to answer your own post and accept that as the answer.
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi anandhalagarasan,
how do you configured your input, do you used TA_Windows?
if not, use TA_Windows, if yes, please share inputs.conf.
Bye.
Giuseppe

0 Karma

anandhalagarasa
Path Finder

Kindly help on this request.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...