Getting Data In

Can Splunk ingest the "Details tab - xml view" of a Windows Event Log?

a548506
Path Finder

Hello All,

We have a customer that we are ingesting a number of windows event logs for ... we are using the pre-defined splunk source-type to ingest these.

We know that splunk captures the "Genera tabl" view details of the event, but our customer is asking if we can ingest the "Details tab" and under that there is a XML view. He is wanting to be able to search on a ID that shows up in the xml that unfortunately does not show in the "General tab" view.

Is splunk able to ingest that xml somehow?

Thanks for the help.

0 Karma
1 Solution

nthornbury
Explorer

I'm able to ingest the XML version of these events just fine. I seem to be having issues with line breaking. I can't seem to nail down the stanza line that will accurately display the data in a readable format. Anyone have a suggestion for the props.conf to achieve this? Thanks.

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Hmmm. Are you in fact using the sourcetype already provided in the TAs referenced here? If so and still having problems it might be stronger to start a new question (feel free to cross reference this one) and provide greater detail.

0 Karma

a548506
Path Finder

@woodcock,

Would I need to download this Splunk_TA_Windows app? Can't tell if i do or it's just as simple as adding that line in my inputs.conf.

Thanks again.

0 Karma

woodcock
Esteemed Legend

You can just add that line and it will change formats. It does not work for Windows (server?) 2003 and has some other caveats so I would read ALL the documentation pages on it.

0 Karma

a548506
Path Finder

@woodcock,

Thanks for the help, it worked. Another question ... is this xml data getting indexed as well? Meaning are we getting "double charged" ?

Thanks again

0 Karma

sloshburch
Splunk Employee
Splunk Employee

@woodcock - you missed a great opportunity to do the Socratic Method on @a548506 😉

@a548506 - How might you check for the answer to your question about licensing? Can you think of any particular dashboards, searches, datasources, etc.. that would facilitate this? Hint

0 Karma

woodcock
Esteemed Legend

The XML is your new data exactly as you see it. The original event format is fully replaced so you are not getting "double".

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...