Hi,
I have to index exported .evxt files on a Windows box. I can process these evtx files with Splunk and events looks likes as in Windows Event viewer's "General" tabs shows it. Unfortunately, because of the structure of the event, I need the events in the format as the "Detailed" tab show them.
So the question: how can I index evtx files in "Detailed" (XML) format? So far renderXml stanza doesn't help me. Currently I user simple Monitor stanza to monitor the directory of the evtx files.
To be more specific: these are NetApp-Security-Audit files, about events accessing shared files. How should I handle this files, does anyone has (good) experience whit them?
Regards,
István
Maarten from support here, I found this after the case you raised with me.
I provided something similar to the answer here:
https://answers.splunk.com/answers/386482/how-to-configure-splunk-to-index-netapp-cifs-logs.html
[netapp-audit]
SHOULD_LINEMERGE=false
LINE_BREAKER=()()
TIME_PREFIX=TimeCreated
KV_MODE=xml