Getting Data In

Windows eventid csv file for Splunk lookup?

maverick
Splunk Employee
Splunk Employee

Does anyone happen to have (or know where I can find) a csv file that contains the various Windows security eventids and their matching humanly-readable meanings so I can use it as my lookup file?

If not, then where is the best page on msdn.com to look for the listing myself so I can compile one?

If I make one myself, then I will share it on splunkbase as an add-on.

Therefore, you can think of it as you are helping me to help you. 🙂

2 Solutions

muebel
SplunkTrust
SplunkTrust

http://pastie.org/1066138.txt

Link to CSV mapping eventcode to event description^

View solution in original post

splk
Communicator
0 Karma

muebel
SplunkTrust
SplunkTrust

http://pastie.org/1066138.txt

Link to CSV mapping eventcode to event description^

maverick
Splunk Employee
Splunk Employee

WOW! Thanks! I appreciate it!

0 Karma

djemodjenai
Explorer

This pastie link may be down.

0 Karma

ftk
Motivator

maverick
Splunk Employee
Splunk Employee

Thanks! This will help.

0 Karma
Get Updates on the Splunk Community!

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...

There's No Place Like Chrome and the Splunk Platform

WATCH NOW!Malware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

Customer Experience | Join the Customer Advisory Board!

Are you ready to take your Splunk journey to the next level? 🚀 We invite you to join our elite squad ...