Getting Data In

Windows event logs - BSD syslog format

thetech
Explorer

Hi all,

I am receiving Windows event logs from a domain controller via an NXLogs agent. This data is being sent over UDP/514 and the data format is in BSD style syslog.

Whilst I am successfully receiving and ingesting this data the problem I have is as follows

  • How do I have splunk successfully parse this data so that it can be used by the Windows TA addon

I am thinking I need to create something in the props.conf maybe?

Any questions please ask

Regards

TheTech

Labels (2)
0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...