All Apps and Add-ons

Windows app and Windows 2008 evtx logs

gsawyer1
Engager

Does the windows app work with 2008 event log files? Is the Windows app the best way to monitor windows logs?

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

The Windows app is the best way to monitor Windows Event Logs, but it doesn't monitor the evtx files. (The files are [or can be] created by the Event Logging system, but the Splunk WinEventLog monitor talks directly to the Event Logging system rather than looking.)

gsawyer1
Engager

So then what is the recommended method for ingesting evtx files from Windows 2008? Also, when I enable and configure the Windows App to monitor my event logs, on both 2003 and 2008 servers, nothing is getting ingested. I verified that my account has full control over the Splunk installation directory. I am now manually entering the Windows stanzas in the inputs.conf file....

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...