All Apps and Add-ons

Windows app and Windows 2008 evtx logs

gsawyer1
Engager

Does the windows app work with 2008 event log files? Is the Windows app the best way to monitor windows logs?

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

The Windows app is the best way to monitor Windows Event Logs, but it doesn't monitor the evtx files. (The files are [or can be] created by the Event Logging system, but the Splunk WinEventLog monitor talks directly to the Event Logging system rather than looking.)

gsawyer1
Engager

So then what is the recommended method for ingesting evtx files from Windows 2008? Also, when I enable and configure the Windows App to monitor my event logs, on both 2003 and 2008 servers, nothing is getting ingested. I verified that my account has full control over the Splunk installation directory. I am now manually entering the Windows stanzas in the inputs.conf file....

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...