Hi all. I have a folder with about 200 evtx files. The following command works for 1 file. How can I process/convert all of the evtx files to csv at once? Thanks.
Get-WinEvent -Path C:\somewhere\foo.evtx | Export-CSV C:\somewhere\foo.csv
This is more of an OS/shell problem than a Splunk problem. You should able to use the shell's looping constructs to iterate over the files in the folder.
Get-ChildItem –Path "C:\somewhere" |
Foreach-Object {
#Do something with $_.FullName
}
I tried this command, modified with get-winevent piped to export-csv but no luck. How do I iterate so it changes each xxx.evtx to xxx.csv, yyy.evtx to yyy.csv, etc. Thanks.
That would be a question for a Powershell forum.