<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows Forwarder not collecting EventLogs in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Windows-Forwarder-not-collecting-EventLogs/m-p/345005#M12827</link>
    <description>&lt;UL&gt;
&lt;LI&gt;I installed windows Universal forwarder on a host as a local user and updated outputs.conf with the Indexer details .&lt;/LI&gt;
&lt;LI&gt;However as per doc , I never got this promt during installation:
&lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.6.1/Data/MonitorWindowseventlogdata" target="_blank"&gt;http://docs.splunk.com/Documentation/SplunkCloud/6.6.1/Data/MonitorWindowseventlogdata&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;"When the installer prompts you to specify inputs, enable the event log inputs by checking the "Event logs" checkbox."&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;I also pushed inputs.conf for eventlog collection via deployment server with the below stanza.
[WinEventLog://Application]
disabled=0
[WinEventLog://Security]
disabled=0
[WinEventLog://System]
disabled=0&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Eventlog data is not getting collected. Also there is no output for the host on the Search Head.&lt;/P&gt;

&lt;P&gt;1) I noticed this error in the splunkd.log on the windows forwarder and I'm not aware of this error, also couldn't find much info on Splunk docs / splunk answers. All I did was installing the forwarder on the host. I never set up any cron for the splunk exe process and Im unable to figure out this error.&lt;/P&gt;

&lt;P&gt;Could someone please guide:&lt;/P&gt;

&lt;P&gt;08-01-2017 06:26:04.223 -0400 ERROR ExecProcessor - message from ""E:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"" splunk-powershell - Powershell::InitPowershell: Stanza get-networklatency. Invalid cron schedule: 0*/5***?&lt;/P&gt;

&lt;P&gt;2) Also Am I missing out an any steps for configuring the windows forwarder Eventlog collection?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 15:11:17 GMT</pubDate>
    <dc:creator>saranya_fmr</dc:creator>
    <dc:date>2020-09-29T15:11:17Z</dc:date>
    <item>
      <title>Windows Forwarder not collecting EventLogs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Windows-Forwarder-not-collecting-EventLogs/m-p/345005#M12827</link>
      <description>&lt;UL&gt;
&lt;LI&gt;I installed windows Universal forwarder on a host as a local user and updated outputs.conf with the Indexer details .&lt;/LI&gt;
&lt;LI&gt;However as per doc , I never got this promt during installation:
&lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.6.1/Data/MonitorWindowseventlogdata" target="_blank"&gt;http://docs.splunk.com/Documentation/SplunkCloud/6.6.1/Data/MonitorWindowseventlogdata&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;"When the installer prompts you to specify inputs, enable the event log inputs by checking the "Event logs" checkbox."&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;I also pushed inputs.conf for eventlog collection via deployment server with the below stanza.
[WinEventLog://Application]
disabled=0
[WinEventLog://Security]
disabled=0
[WinEventLog://System]
disabled=0&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Eventlog data is not getting collected. Also there is no output for the host on the Search Head.&lt;/P&gt;

&lt;P&gt;1) I noticed this error in the splunkd.log on the windows forwarder and I'm not aware of this error, also couldn't find much info on Splunk docs / splunk answers. All I did was installing the forwarder on the host. I never set up any cron for the splunk exe process and Im unable to figure out this error.&lt;/P&gt;

&lt;P&gt;Could someone please guide:&lt;/P&gt;

&lt;P&gt;08-01-2017 06:26:04.223 -0400 ERROR ExecProcessor - message from ""E:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"" splunk-powershell - Powershell::InitPowershell: Stanza get-networklatency. Invalid cron schedule: 0*/5***?&lt;/P&gt;

&lt;P&gt;2) Also Am I missing out an any steps for configuring the windows forwarder Eventlog collection?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:11:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Windows-Forwarder-not-collecting-EventLogs/m-p/345005#M12827</guid>
      <dc:creator>saranya_fmr</dc:creator>
      <dc:date>2020-09-29T15:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Forwarder not collecting EventLogs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Windows-Forwarder-not-collecting-EventLogs/m-p/345006#M12828</link>
      <description>&lt;P&gt;Start it over. Reinstall the forwarder and accept defaults. Only set the deployment server values during the install. Then make sure the respective apps are installed from the deployment server. If not, then start there.&lt;/P&gt;

&lt;P&gt;Also, make sure you have network connectivity between this endpoint and the indexers as well as the deployment server. I've seen many hours wasted on Splunk when it turns out it's just a networking blockage.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 18:43:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Windows-Forwarder-not-collecting-EventLogs/m-p/345006#M12828</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-08-02T18:43:54Z</dc:date>
    </item>
  </channel>
</rss>

