Splunk Enterprise

Powershell to Splunk issue - eventlog

Stngr
New Member

Hi there,

I've configured custom application logs to go to Splunk with .ps1 script.

The problem is - some logs are missing... After some troubleshoot I found there is something in the message property that makes it fail, as if I exclude message all events are processed (yet useless).

My guess is - there is something considered as exit character in the message that fails to be ingested. 

Have nothing set in props.conf

 

Sample message that gets processed:

Feature audited:                   Scheduled Task

Type of Change:                   Edit Scheduled Task

Changed by:                          DOMAIN\svc_landesk

Date of change:                    11/19/2020 13:56:17

Changed on machine:         SERVERVLANDE01

Item name:                            Run After Image - 11/19/2020 1:54:40 PM

Old value:                             

Feature Specific Data:

Data too big.  See equivalent event in the database.

 

Sample message that fails and doesnt show up in splunk:

Feature audited:                   Scheduled Task

Type of Change:                   Start Scheduled Task

Changed by:                          DOMAIN\svc_landesk

Date of change:                    11/19/2020 13:56:17

Changed on machine:         SERVERVLANDE01

Item name:                           

Old value:                             

Feature Specific Data:

<ExportableChange xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" />

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...