Splunk Search

Windows app and evtx files

gsawyer1
Engager

So then what is the recommended method for ingesting evtx files from Windows 2008? Also, when I enable and configure the Windows App to monitor my event logs, on both 2003 and 2008 servers, nothing is getting ingested. I verified that my account has full control over the Splunk installation directory. I am now manually entering the Windows stanzas in the inputs.conf file....

Tags (1)
0 Karma

ftk
Motivator

Does the account you are running Splunk under have sufficient privileges to access the Windows event logs in question?

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Do you want to monitor the Event Logs, or do you want to load *.evtx files? The files are a byproduct of Windows Logging. If you want to log data, you should use Splunk's Windows Event Log monitoring, and forget about the files. Importing or monitoring the *.evtx files can be done, but is most useful if somehow you have copied them over away from the system where they are being generated.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...