Cribl Handling XML Windows Event Logs

preview_player
Показать описание
If you handle XML Windows EventLogs, you probably agree that the logs are hard to parse and are verbose. They take up a large amount of storage space and ultimately affect cpu and ram on your Splunk instance.

Cribl provides an easy ability to convert XML Windows EventLogs to Key Value pairs and reduce the size of the logs close to 50-70 percent.

The process to convert WinEvent Logs to a key value is outlined in this following web page.

To view playlist all about Cribl use the following:

The latest L.A.M.E. Splunk apps are available at
Рекомендации по теме
Комментарии
Автор

Love this series, looking forward for more Cribl content!

NitesphirE