<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Message &amp;quot;Eventtype 'wineventlog-ds' does not exist or is disabled&amp;quot; appears in splunk app for *nix in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278479#M63367</link>
    <description>&lt;P&gt;now i see the DS error but not the DNS error, how does one get rid off the ds error?  I just upgraded 1.3&lt;BR /&gt;
Eventtype 'wineventlog-ds' does not exist or is disabled&lt;/P&gt;</description>
    <pubDate>Tue, 16 Aug 2016 20:56:16 GMT</pubDate>
    <dc:creator>mtime24</dc:creator>
    <dc:date>2016-08-16T20:56:16Z</dc:date>
    <item>
      <title>Message "Eventtype 'wineventlog-ds' does not exist or is disabled" appears in splunk app for *nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278473#M63361</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/1631i7473D026E2D932BC/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I installed the app for windows infrastucture, then the app for *nix.  Now, when i go in to the app for *nix, I get a message at the top saying eventtypes for wineventlog-ds and wineventlog-dns do not exist.  This message doesn't appear any where else.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2016 10:47:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278473#M63361</guid>
      <dc:creator>gregbo</dc:creator>
      <dc:date>2016-07-22T10:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Eventtype 'wineventlog-ds' does not exist or is disabled" appears in splunk app for *nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278474#M63362</link>
      <description>&lt;P&gt;There are pre-req's that are required to have the correct knowledge objects for Windows Infrastructure app.  If these are not on the same Search Head as the windows infrastructure app it will give you those errors.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/MSApp/1.3.0/MSInfra/Platformandhardwarerequirements#The_Splunk_Add-ons_for_Microsoft_Active_Directory_and_Windows_DNS_v1.0.0_or_later" target="_blank"&gt;http://docs.splunk.com/Documentation/MSApp/1.3.0/MSInfra/Platformandhardwarerequirements#The_Splunk_Add-ons_for_Microsoft_Active_Directory_and_Windows_DNS_v1.0.0_or_later&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The Splunk Add-ons for Microsoft Active Directory and Windows DNS v1.0.0 or later&lt;/P&gt;

&lt;P&gt;The suite of Splunk Add-ons for Active Directory must be installed on universal forwarders in the Windows deployment.&lt;/P&gt;

&lt;P&gt;You can download the Splunk Add-ons for Microsoft Active Directory and Windows DNS from Splunkbase. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:23:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278474#M63362</guid>
      <dc:creator>tsweet_splunk</dc:creator>
      <dc:date>2020-09-29T10:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Eventtype 'wineventlog-ds' does not exist or is disabled" appears in splunk app for *nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278475#M63363</link>
      <description>&lt;P&gt;Thanks!  Turns out I had missed a couple of the Add-ons that were required!&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2016 17:48:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278475#M63363</guid>
      <dc:creator>mschmunk06</dc:creator>
      <dc:date>2016-07-26T17:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Eventtype 'wineventlog-ds' does not exist or is disabled" appears in splunk app for *nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278476#M63364</link>
      <description>&lt;P&gt;But I'm not using Active Directory or windows DNS on these servers.  Also, the error only shows up in the App for *nix.  &lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2016 09:27:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278476#M63364</guid>
      <dc:creator>gregbo</dc:creator>
      <dc:date>2016-07-27T09:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Eventtype 'wineventlog-ds' does not exist or is disabled" appears in splunk app for *nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278477#M63365</link>
      <description>&lt;P&gt;If you have the Windows Infrastructure app installed on this SH, it requires knowledge objects from the AD and DNS apps so these need to be installed to make those messages go away. &lt;/P&gt;

&lt;P&gt;The alternative is to disable the eventtypes (which if you are not using AD or DNS should not have any impact on the Windows Infrastructure functionality) &lt;/P&gt;

&lt;P&gt;Create a /splunk_app_windows_infrastructure/local/eventtypes.conf file with the following to disable the unneeded eventtypes.  This should suppress those messages&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[msad-anomalous-events]
disabled=1

[msad-dirsvcs-anomalous-events]
disabled=1

[msad-rep-errors]
disabled=1

[msad-dns-events]
disabled=1
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:22:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278477#M63365</guid>
      <dc:creator>tsweet_splunk</dc:creator>
      <dc:date>2020-09-29T10:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Eventtype 'wineventlog-ds' does not exist or is disabled" appears in splunk app for *nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278478#M63366</link>
      <description>&lt;P&gt;I just encountered this issue after upgrading Infrastructure app from 1.2 to 1.3, installed dns app and now alert is gone......thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 20:51:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278478#M63366</guid>
      <dc:creator>mtime24</dc:creator>
      <dc:date>2016-08-16T20:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Eventtype 'wineventlog-ds' does not exist or is disabled" appears in splunk app for *nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278479#M63367</link>
      <description>&lt;P&gt;now i see the DS error but not the DNS error, how does one get rid off the ds error?  I just upgraded 1.3&lt;BR /&gt;
Eventtype 'wineventlog-ds' does not exist or is disabled&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 20:56:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278479#M63367</guid>
      <dc:creator>mtime24</dc:creator>
      <dc:date>2016-08-16T20:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Eventtype 'wineventlog-ds' does not exist or is disabled" appears in splunk app for *nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278480#M63368</link>
      <description>&lt;P&gt;Active Directory app is also needed:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3207/"&gt;https://splunkbase.splunk.com/app/3207/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;enjoy&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 20:57:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278480#M63368</guid>
      <dc:creator>tsweet_splunk</dc:creator>
      <dc:date>2016-08-16T20:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Eventtype 'wineventlog-ds' does not exist or is disabled" appears in splunk app for *nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278481#M63369</link>
      <description>&lt;P&gt;TY....I had the wrong app installed, I installed Splunk Supporting Add-on for Active Directory instead of Splunk Add-on for Microsoft Active Directory....issue solved, thanks for the second pair of eyes &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 21:12:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278481#M63369</guid>
      <dc:creator>mtime24</dc:creator>
      <dc:date>2016-08-16T21:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Eventtype 'wineventlog-ds' does not exist or is disabled" appears in splunk app for *nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278482#M63370</link>
      <description>&lt;P&gt;To resolve this I disabled export=system in default meta here: /splunk_app_windows_infrastructure/metadata &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[eventtypes]
export = None
# export = system
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Changed it to export=none so that other apps are not trying to use the eventtypes from the windows infra app.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:00:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278482#M63370</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-09-29T13:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Eventtype 'wineventlog-ds' does not exist or is disabled" appears in splunk app for *nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278483#M63371</link>
      <description>&lt;P&gt;I tried this solutions but then some of my other reports that use the SPLUNK App For Windows Infrastructure stopped showing reults.&lt;/P&gt;

&lt;P&gt;[eventtypes]&lt;BR /&gt;
 export = None&lt;BR /&gt;
 # export = system&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 18:57:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278483#M63371</guid>
      <dc:creator>s_dparker</dc:creator>
      <dc:date>2017-10-30T18:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Eventtype 'wineventlog-ds' does not exist or is disabled" appears in splunk app for *nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278484#M63372</link>
      <description>&lt;P&gt;export = app1, app2, etc&lt;/P&gt;

&lt;P&gt;Where app1 and app2 are the apps that need it&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 22:27:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278484#M63372</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-10-30T22:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Eventtype 'wineventlog-ds' does not exist or is disabled" appears in splunk app for *nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278485#M63373</link>
      <description>&lt;P&gt;Previous solutions did not work for me.  Might be due to version differences.&lt;/P&gt;

&lt;P&gt;What worked for me was simply adding the wineventlog-ds eventtype to the app for windows infrastructure.&lt;/P&gt;

&lt;P&gt;IE from within the Splunk App for Windows Infrastructure, click Settings --&amp;gt; Event Types --&amp;gt; New Event Type&lt;/P&gt;

&lt;P&gt;and add an event type as per the screenshot below:&lt;BR /&gt;
&lt;IMG src="https://i.imgsafe.org/9d/9d900d1c7b.png" alt="https://i.imgsafe.org/9d/9d900d1c7b.png" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 20:37:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278485#M63373</guid>
      <dc:creator>tnesavich_splun</dc:creator>
      <dc:date>2019-05-01T20:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Eventtype 'wineventlog-ds' does not exist or is disabled" appears in splunk app for *nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278486#M63374</link>
      <description>&lt;P&gt;I was able to resolve this by editing this file:&lt;/P&gt;

&lt;P&gt;C:\Program Files\Splunk\etc\apps\splunk_app_windows_infrastructure\default\eventtypes.conf &lt;/P&gt;

&lt;P&gt;(and doing find-&amp;gt;  "wineventlog-dns" ) and then commenting out that one stanza (was a stanza not relevant to me, espeically since it wasnt working anyway).    I did the same thing for "wineventlog-ds" as i was getting an error on that as well.  tks&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:13:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Message-quot-Eventtype-wineventlog-ds-does-not-exist-or-is/m-p/278486#M63374</guid>
      <dc:creator>spunk311z</dc:creator>
      <dc:date>2020-09-30T04:13:10Z</dc:date>
    </item>
  </channel>
</rss>

