Splunk Search

WinEventLog - Appliction and Services Logs- Does anyone have a doc or suggestion?

ttiller
Engager

Trying to collect information from a sub folder in a Windows server event log. Specifically in the Applications and Services Logs/DFS Replication folder. So far it looks like I need to add some info to my local conf file, but unsure of the proper syntax. I believe it would be along these lines:

[WinEventLog:"Application and Services Logs/DFSReplication"]
disabled=0
start from=oldest
currentonly=0

Can anyone point me to the proper doc to figure this out or offer a suggestion. Thanks in advance.

 

 

Labels (1)
Tags (1)
0 Karma

wcolgate_splunk
Splunk Employee
Splunk Employee

The syntax for Windows event log stanza is:

[WinEventLog://<channel-name>]

0 Karma

richgalloway
SplunkTrust
SplunkTrust
Have you tried removing the quotation marks from the stanza name?
---
If this reply helps you, Karma would be appreciated.
0 Karma

ttiller
Engager

The adjustment was  made on the backend so now my search should be successful. Thank you for your suggestion.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If your problem is resolved, then please click the "Accept as Solution" button to help future readers.

---
If this reply helps you, Karma would be appreciated.

ttiller
Engager

I have not. I was unsure if I was even on the right track and did not want to jump off the cliff without some assurances that I'm not going to screw something up. "Nothing ventured nothing gained" as they say. Will give it a go and let you know. Thanks

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...