Getting Data In

Can Windows Events and pcap files can be loaded into Splunk

Douggg
Explorer

Does anyone know if Splunk can import Microsoft Event files or cap, pacp, pcapng files from programs like Wireshark, Network Minder etc?

I’m not a Senior Engineer but I thought cap, pcap and pcapng have been an industry standard file format for 25 years. Same with Microsoft event logs. Is she correct? Splunk doesn’t understand Microsoft event files or Wireshark pcap files?

Is there anyone at Splunk who has worked with Microsoft Event files or pcap files who might have a sample? Our Splunk Engineer wants us to submit sample files but I don’t have any sanitized files to give her. I’m hoping someone at Splunk can help me out.

Thanks

Tags (2)
0 Karma

w0lverineNOP
Path Finder

A little late in responding but a app called stream indexes pcaps!!

0 Karma

Douggg
Explorer

Is there any Splunk documention I can have our Splunk Senior Engineer read? Or do you know if anyone at Splunk knows about this I can refer our Splunk Senior Engineer to?

0 Karma

jtrucks
Splunk Employee
Splunk Employee

Yes, all those things can be ingested into Splunk. The Microsoft Event Logs are parsed by Splunk core. The pcaps are more complex and that isn't a fully solved problem, but there are many ways you can do that on your own or with future enhancements that are likely being worked on today.

I should add that the Sourcefire eStreamer Splunk app does contain pcap data as sent from Sourcefire, but I don't think it is designed to read libpcap format files directly.

--
Jesse Trucks
Minister of Magic
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...