Security

UF evtx on linux

hmq321
New Member

we have UF on Linux machine and we monitor a directory we upload all evtx file to that directory and index them to the windows machine indexer with no luck.

is it possible to do this or we need to use windows machine as UF.

Thank you.

Tags (1)
0 Karma

nickhills
Ultra Champion

Evtx files are binary. They can only be opened by the windows event viewer.

You should use wef to forward events to a wef collector, and ingest them on that server with a UF

If my comment helps, please give it a thumbs up!
0 Karma

hmq321
New Member

not sure but i have seen it working. the only limitation is that I am using a Linux box as universal forwarder and the indexer is windows and it can use whatever dll or api is needed to open the evtx file.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...