Getting Data In

On a Linux Splunk Server, how do I ingest Windows CIFS audit files

rruth
Engager

I have adtlog.evt files I wish to look at from Splunk. How do I do this without using a Windows Splunk server? (I do have universal forwarders on some Windows systems if I need to go that route.) My Splunk server resides on Linux.

Details: I have a Netapp filer with CIFS mounts creating the adtlog.evt files and I want to use Splunk to search them.

0 Karma
1 Solution

rruth
Engager
0 Karma

Richfez
SplunkTrust
SplunkTrust

I don't think this will be easy. You could try something like evtviewer. Note I am not endorsing this, just suggesting it as a way to read those files. I have no idea how you would get that to export the files into a better format. To be honest, I'm not even sure Windows would have an easy way to do this.

Can you have it pick a different logging format? Does the control station (or whatever Netapp uses to "control" the filer) have a console you can get onto? Can you install software there? Does it have another log folder somewhere?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...