Installation

Index EVTX files on Splunk running on non-Windows box

miteshvohra
Contributor

I am running Splunk for Mac (Darwin) on my laptop. I have received handful of EVTX files for analysis from a project team trying to visualize events captured in these event files. I understand that, EVTX files requires Windows APIs and DLLs to index or run Splunk on Windows to index them correctly.

However, is there a workaround to get these EVTX files indexed on Splunk instance running on Mac?

Please suggest.

Tags (2)
0 Karma

kristian_kolb
Ultra Champion

I think you'll need to get them to give you the information you need.

Install an agent on the windows machine capable of producing 'correct' events. Splunk Universal Forwarder is very good, Snare might also work.

If that for some reason is not possible, they might have some luck with LogParser.

http://en.wikipedia.org/wiki/Logparser
http://technet.microsoft.com/en-us/library/ee692937.aspx

Not really familiar with that tool, though.

/K

0 Karma

miteshvohra
Contributor

Noted. Have asked them to setup Free lic of Splunk. Have offered them remote assistance once they are ready.

0 Karma

kristian_kolb
Ultra Champion

tell the project team to redo it. they can't expect you to do a proper analysis with deficient data.

miteshvohra
Contributor

Hi Kristian, Thanks for the help.

Unfortunately, I have received the EVTX files as email attachments.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...