SPL2 templates and modules for Microsoft Windows logs¶
SPL2 content for Microsoft Windows currently includes two artifact types:
- Templates, which are end-to-end SPL2 pipelines for transforming or reducing log data.
- Field-extraction modules, which are reusable SPL2 functions generated from add-on knowledge objects such as
props.confandtransforms.conf.
Templates and modules are available for the Edge Processor and Ingest Processor. See the following documentation for more information:
Templates¶
Transform and reduction templates¶
| Template name | Version | Use case | Availability |
|---|---|---|---|
| Windows event logs: Convert logs from XML to JSON | 0.2.1 | Convert Windows event logs from XML to JSON, reduce the size of the logs by removing unnecessary data, and extract event fields to ensure compatibility with the Splunk Add-on for Microsoft Windows and the Splunk Common Information Model (CIM). | Edge Processor and Ingest Processor |
See the Release notes for SPL2 template release notes.
Modules¶
For information about available SPL2 modules, see the SPL2 modules overview.