<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ** windows sytem logs are not coming to splunk ** in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740788#M81641</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I did'nt modify the&amp;nbsp;serverName on my instance.&lt;/P&gt;&lt;P&gt;If i search "index=_internal source=*splunkd.log" - I would see the 2&amp;nbsp; sources in the interested fields.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AL3Z_0-1741104978173.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/37988i1B237EF9DE275247/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AL3Z_0-1741104978173.png" alt="AL3Z_0-1741104978173.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I had configured the forwarding of the data from UF and the main instance both using port 9997.&lt;BR /&gt;&lt;BR /&gt;In real time uf and server should not be on the same machine right?&lt;/P&gt;&lt;P&gt;Thanks..&lt;/P&gt;</description>
    <pubDate>Tue, 04 Mar 2025 16:24:14 GMT</pubDate>
    <dc:creator>AL3Z</dc:creator>
    <dc:date>2025-03-04T16:24:14Z</dc:date>
    <item>
      <title>** windows system logs are not coming to splunk **</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740689#M81629</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I set up a Splunk lab on my Windows 10 laptop, where both the Splunk Forwarder and Splunk Server are installed on the same host. After installing the Splunk Add-on for Windows, I created an inputs.conf file in the local folder under etc/apps.&lt;/P&gt;&lt;P&gt;###### OS Logs ######&lt;BR /&gt;[WinEventLog://Application]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = "windows_logs"&lt;BR /&gt;start_from = oldest&lt;BR /&gt;current_only = 0&lt;BR /&gt;checkpointInterval = 5&lt;BR /&gt;renderXml=0&lt;BR /&gt;&lt;BR /&gt;Despite this setup, I don't see any Windows logs in Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 10:19:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740689#M81629</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2025-03-04T10:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: ** windows sytem logs are not coming to splunk **</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740690#M81630</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@AL3Z&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just for clarity, did you put the inputs.conf within an app folder in $SPLUNK_HOME/etc/apps (e.g $SPLUNK_HOME/etc/apps/yourApp/local/inputs.conf ? Rather than&amp;nbsp;$SPLUNK_HOME/etc/apps/local/inputs.conf (incorrect) ?&lt;/P&gt;&lt;P&gt;When you refer to "&lt;SPAN&gt;Splunk Forwarder and Splunk Server are installed on the same host" - Is this two deployments of Splunk on the same instance? If so, have you confirmed that your forwarder deployment is able to send its internal logs to the main instance.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please review the _internal logs logs to confirm your forwarder is sending logs to your main Splunk instance (if applicable) and also if there are any errors relating to the Windows TA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 08:43:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740690#M81630</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-04T08:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: ** windows sytem logs are not coming to splunk **</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740701#M81631</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@AL3Z&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;i don't think that you can install on the same VM both Spunk Enterprise and Splunk Universal Forwarder because they have the same IP and hostname and it's completely unuseful.&lt;/P&gt;&lt;P&gt;If you want to test the windows logs ingestion from the local machine, you don't need to use the UF and you can use your Splunk instance to create the input (you can do it also by GUI but It's always better to use the Splunk_TA_Windows enabling the interesting inputs).&lt;/P&gt;&lt;P&gt;If instead you want to test the connection between an UF and an Indexer, you have to use two different VMs and, on the UF, install the Splunk_TA_Windows enabling the interesting inputs.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 09:40:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740701#M81631</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-03-04T09:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: ** windows sytem logs are not coming to splunk **</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740705#M81632</link>
      <description>&lt;P&gt;Hi, &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; I had placed the inputs.conf file within an app folder $SPLUNK_HOME/etc/apps/yourApp/local/inputs.conf only.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;Splunk Forwarder and Splunk Server are installed on the same host,&amp;nbsp;&amp;nbsp;yes forwarder deployment is sending its internal logs to the main instance.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 10:04:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740705#M81632</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2025-03-04T10:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: ** windows system logs are not coming to splunk **</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740718#M81633</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Adding the inputs to&amp;nbsp; C:\Program Files\SplunkUniversalForwarder\etc\system\local&lt;BR /&gt;I can able to see the logs in splunk.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 10:58:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740718#M81633</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2025-03-04T10:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: ** windows sytem logs are not coming to splunk **</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740724#M81634</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@AL3Z&lt;/a&gt;&amp;nbsp;So you are seeing 2 hostnames in your internal logs?&lt;/P&gt;&lt;P&gt;And/Or sources from both:&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd.log&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;and&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;C:\Program Files\Splunk\var\log\splunk\splunkd.log&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Does the&amp;nbsp;&lt;SPAN&gt;windows_logs index exist on your main Splunk instance?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In the context of the SplunkUniversalForwarder, can you run:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;C:\Program Files\SplunkUniversalForwarder\bin\splunk cmd btool inputs list&lt;/LI-CODE&gt;&lt;P&gt;Do your expected Windows inputs get listed?&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 11:14:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740724#M81634</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-04T11:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: ** windows system logs are not coming to splunk **</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740751#M81635</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@AL3Z&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;let us know if we can help you more, or, please, accept one answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 11:55:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740751#M81635</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-03-04T11:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: ** windows sytem logs are not coming to splunk **</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740762#M81636</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;I'm seeing only the 1 hostname in the internal logs.&lt;/P&gt;&lt;P&gt;Yes windows_logs index exist on main Splunk instance.&lt;/P&gt;&lt;P&gt;When i ran the btool cmd i can see the windows inputs list.&lt;BR /&gt;&lt;BR /&gt;Thanks..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 13:30:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740762#M81636</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2025-03-04T13:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: ** windows sytem logs are not coming to splunk **</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740763#M81637</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@AL3Z&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Okay, so that tells us that the inputs on the UF should be working, however the single hostname in the _internal log is inconclusive, as if the UF is on the same server as the main instance it would have the same hostname unless you have specifically modified the serverName on one of the instance? As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;mentioned, having both on the same server/machine will be making things more complicated.&lt;/P&gt;&lt;P&gt;Essentially what we're trying to establish here is if the flow isnt going from the UF, or if the input isnt working. Im starting to suspect that the data isnt going from the UF, so I think it would be good to establish some proof either way.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you search "index=_internal source=*splunkd.log" - How many source do you see in the interested fields on the left? If the UF is sending then you should see 2.&lt;/P&gt;&lt;P&gt;How have you configured the forwarding of the data from UF the main instance, and how have you configured the main instance to listen (Presumably on port 9997)?&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 13:49:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740763#M81637</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-04T13:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: ** windows sytem logs are not coming to splunk **</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740788#M81641</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I did'nt modify the&amp;nbsp;serverName on my instance.&lt;/P&gt;&lt;P&gt;If i search "index=_internal source=*splunkd.log" - I would see the 2&amp;nbsp; sources in the interested fields.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AL3Z_0-1741104978173.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/37988i1B237EF9DE275247/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AL3Z_0-1741104978173.png" alt="AL3Z_0-1741104978173.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I had configured the forwarding of the data from UF and the main instance both using port 9997.&lt;BR /&gt;&lt;BR /&gt;In real time uf and server should not be on the same machine right?&lt;/P&gt;&lt;P&gt;Thanks..&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 16:24:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/windows-system-logs-are-not-coming-to-splunk/m-p/740788#M81641</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2025-03-04T16:24:14Z</dc:date>
    </item>
  </channel>
</rss>

