Installation

Index EVTX files on Splunk running on non-Windows box

miteshvohra
Contributor

I am running Splunk for Mac (Darwin) on my laptop. I have received handful of EVTX files for analysis from a project team trying to visualize events captured in these event files. I understand that, EVTX files requires Windows APIs and DLLs to index or run Splunk on Windows to index them correctly.

However, is there a workaround to get these EVTX files indexed on Splunk instance running on Mac?

Please suggest.

Tags (2)
0 Karma

kristian_kolb
Ultra Champion

I think you'll need to get them to give you the information you need.

Install an agent on the windows machine capable of producing 'correct' events. Splunk Universal Forwarder is very good, Snare might also work.

If that for some reason is not possible, they might have some luck with LogParser.

http://en.wikipedia.org/wiki/Logparser
http://technet.microsoft.com/en-us/library/ee692937.aspx

Not really familiar with that tool, though.

/K

0 Karma

miteshvohra
Contributor

Noted. Have asked them to setup Free lic of Splunk. Have offered them remote assistance once they are ready.

0 Karma

kristian_kolb
Ultra Champion

tell the project team to redo it. they can't expect you to do a proper analysis with deficient data.

miteshvohra
Contributor

Hi Kristian, Thanks for the help.

Unfortunately, I have received the EVTX files as email attachments.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...