Skip to content

SPL2 templates and modules for Microsoft Windows logs

SPL2 content for Microsoft Windows currently includes two artifact types:

  • Templates, which are end-to-end SPL2 pipelines for transforming or reducing log data.
  • Field-extraction modules, which are reusable SPL2 functions generated from add-on knowledge objects such as props.conf and transforms.conf.

Templates and modules are available for the Edge Processor and Ingest Processor. See the following documentation for more information:

Templates

Transform and reduction templates

Template name Version Use case Availability
Windows event logs: Convert logs from XML to JSON 0.2.1 Convert Windows event logs from XML to JSON, reduce the size of the logs by removing unnecessary data, and extract event fields to ensure compatibility with the Splunk Add-on for Microsoft Windows and the Splunk Common Information Model (CIM). Edge Processor and Ingest Processor

See the Release notes for SPL2 template release notes.

Modules

For information about available SPL2 modules, see the SPL2 modules overview.