<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to Collect SMBServer/Audit logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/565976#M100656</link>
    <description>&lt;P&gt;I have been unable to get the universal forwarders to correctly collect the SMB Server audit logs. The inputs.conf file on the deployment server has the following stanza configured but there are no logs flowing in. The other events in the inputs file work without any issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;## Application and Services Logs - SMB Server Audit Log&lt;BR /&gt;[WinEventLog://Microsoft-Windows-SMBServer/Audit]&lt;BR /&gt;index = wineventlog&lt;BR /&gt;disabled = 0&lt;BR /&gt;start_from = oldest&lt;BR /&gt;current_only = 0&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Sep 2021 07:00:42 GMT</pubDate>
    <dc:creator>CJHindmarsh</dc:creator>
    <dc:date>2021-09-06T07:00:42Z</dc:date>
    <item>
      <title>Unable to Collect SMBServer/Audit logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/565976#M100656</link>
      <description>&lt;P&gt;I have been unable to get the universal forwarders to correctly collect the SMB Server audit logs. The inputs.conf file on the deployment server has the following stanza configured but there are no logs flowing in. The other events in the inputs file work without any issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;## Application and Services Logs - SMB Server Audit Log&lt;BR /&gt;[WinEventLog://Microsoft-Windows-SMBServer/Audit]&lt;BR /&gt;index = wineventlog&lt;BR /&gt;disabled = 0&lt;BR /&gt;start_from = oldest&lt;BR /&gt;current_only = 0&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Sep 2021 07:00:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/565976#M100656</guid>
      <dc:creator>CJHindmarsh</dc:creator>
      <dc:date>2021-09-06T07:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Collect SMBServer/Audit logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/573223#M101397</link>
      <description>&lt;P&gt;Hey, were you able to get this working?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 18:59:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/573223#M101397</guid>
      <dc:creator>km1986</dc:creator>
      <dc:date>2021-11-01T18:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Collect SMBServer/Audit logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/575116#M101653</link>
      <description>&lt;P&gt;Is that the correct path of where those logs are actually located? Also, you are going to want to make sure that Splunk is able to capture from that location. Might want to check permissions on the windows event log configuration.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 19:09:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/575116#M101653</guid>
      <dc:creator>adobrzeniecki</dc:creator>
      <dc:date>2021-11-16T19:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Collect SMBServer/Audit logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/575158#M101661</link>
      <description>&lt;P&gt;Yep, the above stanza is correct. I was just impatient I think. The next morning I had pretty much all the logs available to search.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 22:16:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/575158#M101661</guid>
      <dc:creator>CJHindmarsh</dc:creator>
      <dc:date>2021-11-16T22:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Collect SMBServer/Audit logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/575419#M101717</link>
      <description>&lt;P&gt;Was splunkd running as SYSTEM or as a domain account? I tried both, restarted Splunk services and the DS, but while other Event IDs are coming as expected the Event ID 3000 (SMBServer Audit) logs are not coming in. Now that it is certain the path is correct, I'm thinking if it something related to permissions.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 10:47:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/575419#M101717</guid>
      <dc:creator>km1986</dc:creator>
      <dc:date>2021-11-18T10:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Collect SMBServer/Audit logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/576064#M101804</link>
      <description>&lt;P&gt;What sourcetype did your data come in with? Did you have to create the sourcetype?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 17:32:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/576064#M101804</guid>
      <dc:creator>adobrzeniecki</dc:creator>
      <dc:date>2021-11-23T17:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Collect SMBServer/Audit logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/576083#M101806</link>
      <description>&lt;P&gt;I was able to fix it. It was permissions on Windows Event Logs. Used &lt;A href="https://support.umbrella.com/hc/en-us/articles/115004063808-Using-wevtutil-to-check-Event-Log-permissions" target="_blank"&gt;https://support.umbrella.com/hc/en-us/articles/115004063808-Using-wevtutil-to-check-Event-Log-permissions&lt;/A&gt;&amp;nbsp;as reference to correct the channel access string for&amp;nbsp;Microsoft-Windows-SMBServer/Audit. Thanks for the suggestion.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 20:47:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/576083#M101806</guid>
      <dc:creator>km1986</dc:creator>
      <dc:date>2021-11-23T20:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Collect SMBServer/Audit logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/576108#M101808</link>
      <description>&lt;P&gt;I was at the time utilizing the Splunk add on for Windows. It came with some predefined sourcetypes for Win Event logs.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 23:35:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Collect-SMBServer-Audit-logs/m-p/576108#M101808</guid>
      <dc:creator>CJHindmarsh</dc:creator>
      <dc:date>2021-11-23T23:35:18Z</dc:date>
    </item>
  </channel>
</rss>

