<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic &amp;quot;Splunk could not get the description for this event&amp;quot; - SplunkUniversalForwarders, versions 4.2 thru 5.0.1 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/quot-Splunk-could-not-get-the-description-for-this-event-quot/m-p/60338#M11956</link>
    <description>&lt;P&gt;I am getting a high incidence rate of "Splunk could not get the description for this event."&lt;BR /&gt;
All forwarders are SplunkUniversalForwarders, versions 4.2 thru 5.0.1.&lt;BR /&gt;
Yesterday I got these results from my Linux 4.3.2 indexer:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;                                Servers with
Splunk Universal  Servers with  "Splunk Could   
Forwarder Ver.    WinEvents OK  not get desc"  Total
   4.2                 27           21           48
   4.2.2                4            2            6
   4.3.1                1            -            1
   4.3.2                4            8           12
   5.0.1              172           40          212
Total                 208           71          279
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Since the results were so scattered among the forwarder versions, I upgraded the indexer to 5.0.2.&lt;BR /&gt;&lt;BR /&gt;
As the indexer is a Linux box, and I know the event descriptions are extracted from the DLL’s on the clients, I really didn’t expect to see a change. However, since the change I now have 151 servers with “could not get” — over twice what I had yesterday before upgrading the indexer. Now over 75% of my windows events contain “Splunk could not get the description for this event.”&lt;/P&gt;

&lt;P&gt;The majority of the events are from the  security logs, but there is also a significant number of events from the system and application event logs.&lt;BR /&gt;&lt;BR /&gt;
Descriptions are present when viewed via event viewer on servers in most cases. In a few cases applications do not put descriptions into the application log.&lt;BR /&gt;&lt;BR /&gt;
A spotcheck of some of the affected servers shows that msaudite.dll file and the security subkey under hklm\system\currentcontrolset\services\eventlog\security are present.&lt;BR /&gt;&lt;BR /&gt;
Operating systems are also a mix — 78 of the effected machines are Server 2008, the rest 2003.&lt;/P&gt;

&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Mar 2013 16:56:53 GMT</pubDate>
    <dc:creator>rgcox1</dc:creator>
    <dc:date>2013-03-13T16:56:53Z</dc:date>
    <item>
      <title>"Splunk could not get the description for this event" - SplunkUniversalForwarders, versions 4.2 thru 5.0.1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/quot-Splunk-could-not-get-the-description-for-this-event-quot/m-p/60338#M11956</link>
      <description>&lt;P&gt;I am getting a high incidence rate of "Splunk could not get the description for this event."&lt;BR /&gt;
All forwarders are SplunkUniversalForwarders, versions 4.2 thru 5.0.1.&lt;BR /&gt;
Yesterday I got these results from my Linux 4.3.2 indexer:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;                                Servers with
Splunk Universal  Servers with  "Splunk Could   
Forwarder Ver.    WinEvents OK  not get desc"  Total
   4.2                 27           21           48
   4.2.2                4            2            6
   4.3.1                1            -            1
   4.3.2                4            8           12
   5.0.1              172           40          212
Total                 208           71          279
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Since the results were so scattered among the forwarder versions, I upgraded the indexer to 5.0.2.&lt;BR /&gt;&lt;BR /&gt;
As the indexer is a Linux box, and I know the event descriptions are extracted from the DLL’s on the clients, I really didn’t expect to see a change. However, since the change I now have 151 servers with “could not get” — over twice what I had yesterday before upgrading the indexer. Now over 75% of my windows events contain “Splunk could not get the description for this event.”&lt;/P&gt;

&lt;P&gt;The majority of the events are from the  security logs, but there is also a significant number of events from the system and application event logs.&lt;BR /&gt;&lt;BR /&gt;
Descriptions are present when viewed via event viewer on servers in most cases. In a few cases applications do not put descriptions into the application log.&lt;BR /&gt;&lt;BR /&gt;
A spotcheck of some of the affected servers shows that msaudite.dll file and the security subkey under hklm\system\currentcontrolset\services\eventlog\security are present.&lt;BR /&gt;&lt;BR /&gt;
Operating systems are also a mix — 78 of the effected machines are Server 2008, the rest 2003.&lt;/P&gt;

&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2013 16:56:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/quot-Splunk-could-not-get-the-description-for-this-event-quot/m-p/60338#M11956</guid>
      <dc:creator>rgcox1</dc:creator>
      <dc:date>2013-03-13T16:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: "Splunk could not get the description for this event" - SplunkUniversalForwarders, versions 4.2 thru 5.0.1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/quot-Splunk-could-not-get-the-description-for-this-event-quot/m-p/60339#M11957</link>
      <description>&lt;P&gt;I had this same issue, it came down to being the version of the forwarder 4.3.2 &lt;/P&gt;

&lt;P&gt;4.3.2 has a known bug and can cause this issue, to resolve this I had to upgrade all my forwarders from this version to 5.0.1&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2013 07:24:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/quot-Splunk-could-not-get-the-description-for-this-event-quot/m-p/60339#M11957</guid>
      <dc:creator>AaronMoorcroft</dc:creator>
      <dc:date>2013-09-17T07:24:47Z</dc:date>
    </item>
  </channel>
</rss>

