<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Eventtype 'wineventlog_security' does not exist or is disabled. in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/461156#M74096</link>
    <description>&lt;P&gt;I take it you have installed the windows TA on your searchhead?&lt;BR /&gt;
I am guessing so, because you said that the event types are set to global.&lt;/P&gt;

&lt;P&gt;Is there any chance you have changed the permissions on the installed TA from apps settings.&lt;BR /&gt;
I have a funny feeling that if you set an event type to global, but in an app that does not give everyone read access you can get these errors.&lt;/P&gt;</description>
    <pubDate>Tue, 04 Feb 2020 11:23:58 GMT</pubDate>
    <dc:creator>nickhills</dc:creator>
    <dc:date>2020-02-04T11:23:58Z</dc:date>
    <item>
      <title>Eventtype 'wineventlog_security' does not exist or is disabled.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/461153#M74093</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/8321iBB38061B725F512B/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am getting a warning after running any search job "Eventtype 'wineventlog_security' does not exist or is disabled." There is a post regarding this (&lt;A href="https://answers.splunk.com/answers/744214/eventtype-wineventlog-security-does-not-exist-or-i.html"&gt;https://answers.splunk.com/answers/744214/eventtype-wineventlog-security-does-not-exist-or-i.html&lt;/A&gt;) and it mentioned there to check that this eventtype is shared globally, and they are globally shared.&lt;/P&gt;

&lt;P&gt;Would anyone know where else I should check? I am on version 8.0.0.&lt;/P&gt;

&lt;P&gt;Thanks and regards&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 10:56:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/461153#M74093</guid>
      <dc:creator>africates</dc:creator>
      <dc:date>2020-02-04T10:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Eventtype 'wineventlog_security' does not exist or is disabled.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/461154#M74094</link>
      <description>&lt;P&gt;Can you post the actual error you are seeing? Perhaps a screen shot?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 11:02:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/461154#M74094</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-02-04T11:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: Eventtype 'wineventlog_security' does not exist or is disabled.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/461155#M74095</link>
      <description>&lt;P&gt;sorry, i thought i have uploaded the image. see updated post. thanks&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 11:15:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/461155#M74095</guid>
      <dc:creator>africates</dc:creator>
      <dc:date>2020-02-04T11:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Eventtype 'wineventlog_security' does not exist or is disabled.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/461156#M74096</link>
      <description>&lt;P&gt;I take it you have installed the windows TA on your searchhead?&lt;BR /&gt;
I am guessing so, because you said that the event types are set to global.&lt;/P&gt;

&lt;P&gt;Is there any chance you have changed the permissions on the installed TA from apps settings.&lt;BR /&gt;
I have a funny feeling that if you set an event type to global, but in an app that does not give everyone read access you can get these errors.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 11:23:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/461156#M74096</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-02-04T11:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: Eventtype 'wineventlog_security' does not exist or is disabled.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/461157#M74097</link>
      <description>&lt;P&gt;hmm, thinking about this, I'm doubting my comment. &lt;BR /&gt;
I'm not near a deployment to check this at the moment..&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 11:25:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/461157#M74097</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-02-04T11:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: Eventtype 'wineventlog_security' does not exist or is disabled.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/461158#M74098</link>
      <description>&lt;P&gt;Hi nick, I have windows TA installed on the forwarders, but not in the server itself.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2020 11:19:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/461158#M74098</guid>
      <dc:creator>africates</dc:creator>
      <dc:date>2020-02-05T11:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Eventtype 'wineventlog_security' does not exist or is disabled.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/461159#M74099</link>
      <description>&lt;P&gt;Oh! You probably want on your indexers and definitely on your search heads.&lt;/P&gt;

&lt;P&gt;("probably" depends on your exact deployment) See:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/WindowsAddOn/7.0.0/User/Install"&gt;https://docs.splunk.com/Documentation/WindowsAddOn/7.0.0/User/Install&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2020 11:23:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/461159#M74099</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-02-05T11:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: Eventtype 'wineventlog_security' does not exist or is disabled.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/560760#M74100</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/3808"&gt;@africates&lt;/a&gt;&amp;nbsp;- I have the same issue, did you find the solution ?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 11:11:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Eventtype-wineventlog-security-does-not-exist-or-is-disabled/m-p/560760#M74100</guid>
      <dc:creator>spodda01da</dc:creator>
      <dc:date>2021-07-26T11:11:50Z</dc:date>
    </item>
  </channel>
</rss>

