Windows event logs - BSD syslog format

Hi all,

I am receiving Windows event logs from a domain controller via an NXLogs agent. This data is being sent over UDP/514 and the data format is in BSD style syslog.

Whilst I am successfully receiving and ingesting this data the problem I have is as follows

  • How do I have splunk successfully parse this data so that it can be used by the Windows TA addon

I am thinking I need to create something in the props.conf maybe?

Any questions please ask



