Security

UF evtx on linux

hmq321
New Member

we have UF on Linux machine and we monitor a directory we upload all evtx file to that directory and index them to the windows machine indexer with no luck.

is it possible to do this or we need to use windows machine as UF.

Thank you.

Tags (1)
0 Karma

nickhills
Ultra Champion

Evtx files are binary. They can only be opened by the windows event viewer.

You should use wef to forward events to a wef collector, and ingest them on that server with a UF

If my comment helps, please give it a thumbs up!
0 Karma

hmq321
New Member

not sure but i have seen it working. the only limitation is that I am using a Linux box as universal forwarder and the indexer is windows and it can use whatever dll or api is needed to open the evtx file.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...