Splunk Search

Windows app and evtx files

gsawyer1
Engager

So then what is the recommended method for ingesting evtx files from Windows 2008? Also, when I enable and configure the Windows App to monitor my event logs, on both 2003 and 2008 servers, nothing is getting ingested. I verified that my account has full control over the Splunk installation directory. I am now manually entering the Windows stanzas in the inputs.conf file....

Tags (1)
0 Karma

ftk
Motivator

Does the account you are running Splunk under have sufficient privileges to access the Windows event logs in question?

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Do you want to monitor the Event Logs, or do you want to load *.evtx files? The files are a byproduct of Windows Logging. If you want to log data, you should use Splunk's Windows Event Log monitoring, and forget about the files. Importing or monitoring the *.evtx files can be done, but is most useful if somehow you have copied them over away from the system where they are being generated.

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...