Splunk Search

rename wineventlog not happening for AWS generic s3

dhanasekar79
New Member

I have downloaded and installed the splunk TA for windows and splunk aws s3 in the search head and the universal forwarder. Created the generic s3 input to point to the S3 bucket storing the windows event logs.

When I run the search query in the indexer "sourcetype="WinEventLog", I am able to see the logs parsed by WinEventLog. However the renaming of the source to WinEventLog:Application seems to be not happening as I don't 'see the rename happening here.

Is there a way for me to troubleshoot this issue.

0 Karma

nickhills
Ultra Champion

How are the win event logs stored in s3?
Are you by chance trying to ingest .evtx files?

If my comment helps, please give it a thumbs up!
0 Karma

dhanasekar79
New Member

Win event logs are exported to S3 bucket from cloudwatch and stored in plain text format. in the aws generic s3 , the source type is set to "WinEventLog" and I see the logs are picked up. But it is not being transformed into "WinEventLog::Security", WinEventLog::Application as dictated in props.conf

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...