<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues with Splunk Universal Forwarder Sending Security Logs After Upgrade to 10.0 in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Issues-with-Splunk-Universal-Forwarder-Sending-Security-Logs/m-p/760254#M24131</link>
    <description>&lt;P&gt;Adding this is case someone has the issue, I upgrader to forwarder to 9.4.4, not 10 but reading this sounds the same. The forwarder ran as system before now runs as local account SplunkForwarder, SplunkForwarder is part of everyone, Our ad audit policy rules had some with everyone on read of anything. this rule caused the security log to log 100k 4662 of splunkforwarder reading an object, that looped upon itself. This caused security events not to forward at times. Reset the forwarder fixed but only for a while. My fix was to change the AD audit policy to be for domain users not everyone.&amp;nbsp; My security events now are loaded timely. To see if this is your issues look in security logs for 4662, by account running the forwarder, if&amp;nbsp; you see thousands of events in a few seconds now and then, this was how I found my issue. Below someone posted to disable lookup which works but wasn't the solution for us because we delete and recreate computer objects all day.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps someone as it took me awhile to find our issue.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Apr 2026 17:34:51 GMT</pubDate>
    <dc:creator>Didalready</dc:creator>
    <dc:date>2026-04-16T17:34:51Z</dc:date>
    <item>
      <title>Issues with Splunk Universal Forwarder Sending Security Logs After Upgrade to 10.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Issues-with-Splunk-Universal-Forwarder-Sending-Security-Logs/m-p/753565#M23130</link>
      <description>&lt;P&gt;Hi Splunk Community,&lt;/P&gt;&lt;P&gt;I recently upgraded my Splunk Universal Forwarders from version 9.4.3 to 10.0, and since the upgrade, I’ve been experiencing issues with the forwarders sending security logs to my Splunk Enterprise instance (which is also running version 10.0).&lt;/P&gt;&lt;P&gt;Here are some specific details:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Pre-upgrade, everything was working fine, and security logs were being ingested without any issues.&lt;/LI&gt;&lt;LI&gt;After the upgrade, I noticed that security logs are either not getting sent or are being delayed significantly.&lt;/LI&gt;&lt;LI&gt;I've verified that the forwarders are still forwarding some logs, but the security-related ones aren't appearing in the index as expected.&lt;/LI&gt;&lt;LI&gt;The configuration files (inputs.conf, outputs.conf, etc.) on the forwarders haven’t been changed since the upgrade.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I’ve tried restarting the forwarders and re-checking the connectivity to the Splunk Enterprise instance, but the issue persists.&lt;/P&gt;&lt;P&gt;Has anyone else encountered similar problems after upgrading to 10.0? Could it be an issue with compatibility, or is there something specific I should look into? Any advice or troubleshooting tips would be greatly appreciated!&lt;/P&gt;&lt;P&gt;Thanks in advance for your help!&lt;/P&gt;</description>
      <pubDate>Wed, 24 Sep 2025 19:16:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Issues-with-Splunk-Universal-Forwarder-Sending-Security-Logs/m-p/753565#M23130</guid>
      <dc:creator>telvinwells08</dc:creator>
      <dc:date>2025-09-24T19:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Splunk Universal Forwarder Sending Security Logs After Upgrade to 10.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Issues-with-Splunk-Universal-Forwarder-Sending-Security-Logs/m-p/753579#M23131</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313238"&gt;@telvinwells08&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my experience there shouldnt be anything that would cause this issue, however Im wondering if there is something else causing these delayed/missed logs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you been able to check $SPLUNK_HOME/var/log/splunk/splunkd.log ? Are there any errors or specific logs relating to security or sending of data which might indicate the cause of the delay? Feel free to share any errors here and we can look into the for you.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 24 Sep 2025 21:11:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Issues-with-Splunk-Universal-Forwarder-Sending-Security-Logs/m-p/753579#M23131</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-09-24T21:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Splunk Universal Forwarder Sending Security Logs After Upgrade to 10.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Issues-with-Splunk-Universal-Forwarder-Sending-Security-Logs/m-p/753757#M23150</link>
      <description>&lt;P&gt;Hi TelvinWell08,&lt;/P&gt;&lt;P&gt;I've had a similar issue recently, did you end up finding out a resolution to this one? Can't seem to get them to send data again?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 14:34:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Issues-with-Splunk-Universal-Forwarder-Sending-Security-Logs/m-p/753757#M23150</guid>
      <dc:creator>SDSplQuestion</dc:creator>
      <dc:date>2025-09-29T14:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Splunk Universal Forwarder Sending Security Logs After Upgrade to 10.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Issues-with-Splunk-Universal-Forwarder-Sending-Security-Logs/m-p/754667#M23309</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I was having the same issues. In the WinEventLog://Security stanza, I changed evt_resolve_ad_obj from 1 to 0 and it finally started working again. Hope this helps!&lt;/P&gt;&lt;PRE&gt;evt_resolve_ad_obj = 0&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Oct 2025 20:37:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Issues-with-Splunk-Universal-Forwarder-Sending-Security-Logs/m-p/754667#M23309</guid>
      <dc:creator>taylormccrary</dc:creator>
      <dc:date>2025-10-23T20:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Splunk Universal Forwarder Sending Security Logs After Upgrade to 10.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Issues-with-Splunk-Universal-Forwarder-Sending-Security-Logs/m-p/760254#M24131</link>
      <description>&lt;P&gt;Adding this is case someone has the issue, I upgrader to forwarder to 9.4.4, not 10 but reading this sounds the same. The forwarder ran as system before now runs as local account SplunkForwarder, SplunkForwarder is part of everyone, Our ad audit policy rules had some with everyone on read of anything. this rule caused the security log to log 100k 4662 of splunkforwarder reading an object, that looped upon itself. This caused security events not to forward at times. Reset the forwarder fixed but only for a while. My fix was to change the AD audit policy to be for domain users not everyone.&amp;nbsp; My security events now are loaded timely. To see if this is your issues look in security logs for 4662, by account running the forwarder, if&amp;nbsp; you see thousands of events in a few seconds now and then, this was how I found my issue. Below someone posted to disable lookup which works but wasn't the solution for us because we delete and recreate computer objects all day.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps someone as it took me awhile to find our issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2026 17:34:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Issues-with-Splunk-Universal-Forwarder-Sending-Security-Logs/m-p/760254#M24131</guid>
      <dc:creator>Didalready</dc:creator>
      <dc:date>2026-04-16T17:34:51Z</dc:date>
    </item>
  </channel>
</rss>

