Security

UF evtx on linux

hmq321
New Member

we have UF on Linux machine and we monitor a directory we upload all evtx file to that directory and index them to the windows machine indexer with no luck.

is it possible to do this or we need to use windows machine as UF.

Thank you.

Tags (1)
0 Karma

nickhills
Ultra Champion

Evtx files are binary. They can only be opened by the windows event viewer.

You should use wef to forward events to a wef collector, and ingest them on that server with a UF

If my comment helps, please give it a thumbs up!
0 Karma

hmq321
New Member

not sure but i have seen it working. the only limitation is that I am using a Linux box as universal forwarder and the indexer is windows and it can use whatever dll or api is needed to open the evtx file.

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...