Getting Data In

Windows Event Logs and Non Standard Importing

smvalois
Explorer

Morning,

We run AD in our environment and the Windows server team does not wish to allow for the use of WMI calls and a service account. They already have a tool called "Event Reporter" which will package windows logs and send them Syslog. Do you know of a way to parse Non standard Windows logs? I either have to figure this out, or remap all the fields by hand using the built in field extractor.

Thank you

Tags (2)
0 Karma

mazurmateusz
Engager

follow up. How you solve your problem?

0 Karma

ltrand
Contributor

You can use the props & transforms.conf files to dictate how to parse this automatically.

http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F

0 Karma

smvalois
Explorer

I know that you can over ride parsers in other products like LogRhyhtm and ArcSight, I am mostly looking to see if i can force a parse on a source, if I know the data type.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...