Security

UF evtx on linux

hmq321
New Member

we have UF on Linux machine and we monitor a directory we upload all evtx file to that directory and index them to the windows machine indexer with no luck.

is it possible to do this or we need to use windows machine as UF.

Thank you.

Tags (1)
0 Karma

nickhills
Ultra Champion

Evtx files are binary. They can only be opened by the windows event viewer.

You should use wef to forward events to a wef collector, and ingest them on that server with a UF

If my comment helps, please give it a thumbs up!
0 Karma

hmq321
New Member

not sure but i have seen it working. the only limitation is that I am using a Linux box as universal forwarder and the indexer is windows and it can use whatever dll or api is needed to open the evtx file.

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...