Getting Data In

Windows eventid csv file for Splunk lookup?

maverick
Splunk Employee
Splunk Employee

Does anyone happen to have (or know where I can find) a csv file that contains the various Windows security eventids and their matching humanly-readable meanings so I can use it as my lookup file?

If not, then where is the best page on msdn.com to look for the listing myself so I can compile one?

If I make one myself, then I will share it on splunkbase as an add-on.

Therefore, you can think of it as you are helping me to help you. 🙂

2 Solutions

muebel
SplunkTrust
SplunkTrust

http://pastie.org/1066138.txt

Link to CSV mapping eventcode to event description^

View solution in original post

splk
Communicator
0 Karma

muebel
SplunkTrust
SplunkTrust

http://pastie.org/1066138.txt

Link to CSV mapping eventcode to event description^

maverick
Splunk Employee
Splunk Employee

WOW! Thanks! I appreciate it!

0 Karma

djemodjenai
Explorer

This pastie link may be down.

0 Karma

ftk
Motivator

maverick
Splunk Employee
Splunk Employee

Thanks! This will help.

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...