Morning,
We run AD in our environment and the Windows server team does not wish to allow for the use of WMI calls and a service account. They already have a tool called "Event Reporter" which will package windows logs and send them Syslog. Do you know of a way to parse Non standard Windows logs? I either have to figure this out, or remap all the fields by hand using the built in field extractor.
Thank you
follow up. How you solve your problem?
You can use the props & transforms.conf files to dictate how to parse this automatically.
http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F
I know that you can over ride parsers in other products like LogRhyhtm and ArcSight, I am mostly looking to see if i can force a parse on a source, if I know the data type.