<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft-Windows-PrintService/Operational Logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77635#M15889</link>
    <description>&lt;P&gt;I can see those logs on the host and I don't have a forwarder installed.&lt;BR /&gt;
I'd like to query without having to install a forwarder. Can this be done?&lt;/P&gt;</description>
    <pubDate>Mon, 30 Sep 2013 23:47:29 GMT</pubDate>
    <dc:creator>corommendoza</dc:creator>
    <dc:date>2013-09-30T23:47:29Z</dc:date>
    <item>
      <title>Microsoft-Windows-PrintService/Operational Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77633#M15887</link>
      <description>&lt;P&gt;I want to monitor who is printing to which printer on my remote print server. Eventually I only want to see event ID 307 however, I'm unable to get any events from that log. I have added the following to my local/inputs.conf:&lt;/P&gt;

&lt;P&gt;[WinEventLog:Microsoft-Windows-PrintService/Operational]&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Data/MonitorWindowsdata#Event_log_monitor_configuration_values"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/Data/MonitorWindowsdata#Event_log_monitor_configuration_values&lt;/A&gt; says I need to import to the Windows Event Viewer but this is already there. I have entered the full path as shown here: &lt;A href="http://answers.splunk.com/answers/6219/windows-2008-server-event-viewer-logs"&gt;http://answers.splunk.com/answers/6219/windows-2008-server-event-viewer-logs&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;What am I missing?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2013 23:17:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77633#M15887</guid>
      <dc:creator>corommendoza</dc:creator>
      <dc:date>2013-09-30T23:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft-Windows-PrintService/Operational Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77634#M15888</link>
      <description>&lt;P&gt;Silly questions, but...&lt;BR /&gt;
Is the local/inputs.conf you mentioned in the forwarder on the hosts connected to the printer?  It won't work on the indexer alone.&lt;BR /&gt;
On the hosts, can you see the logs you're after in the Windows event viewer?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2013 23:27:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77634#M15888</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-09-30T23:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft-Windows-PrintService/Operational Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77635#M15889</link>
      <description>&lt;P&gt;I can see those logs on the host and I don't have a forwarder installed.&lt;BR /&gt;
I'd like to query without having to install a forwarder. Can this be done?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2013 23:47:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77635#M15889</guid>
      <dc:creator>corommendoza</dc:creator>
      <dc:date>2013-09-30T23:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft-Windows-PrintService/Operational Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77636#M15890</link>
      <description>&lt;P&gt;If it can be done, then it would be with the WMI log interface.  Gonna have to think about that one.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2013 23:55:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77636#M15890</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-09-30T23:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft-Windows-PrintService/Operational Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77637#M15891</link>
      <description>&lt;P&gt;I've seen a few old posts about this that are unanswered,  and no answered ones.  This usually means a configuration problem. &lt;BR /&gt;
Have you tried enabling WMI logging for these remote hosts?&lt;BR /&gt;&lt;BR /&gt;
Are you running the main splunkd service with a domain account that has access to these logs?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2013 00:06:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77637#M15891</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-10-01T00:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft-Windows-PrintService/Operational Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77638#M15892</link>
      <description>&lt;P&gt;Yes I can view events on that server remotely via event viewer. Splunk service is running with a domain account that has access.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2013 15:04:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77638#M15892</guid>
      <dc:creator>corommendoza</dc:creator>
      <dc:date>2013-10-01T15:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft-Windows-PrintService/Operational Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77639#M15893</link>
      <description>&lt;P&gt;I meant, have you tried enabling the Splunk WMI input for these logs?&lt;BR /&gt;
Manager&amp;gt;Data Inputs&amp;gt;Remote Event Log Collections&lt;BR /&gt;
Select Add New, enter server name, and try to "find the logs".&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2013 15:58:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77639#M15893</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-10-01T15:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft-Windows-PrintService/Operational Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77640#M15894</link>
      <description>&lt;P&gt;Yes, I only get these:&lt;/P&gt;

&lt;P&gt;Application&lt;BR /&gt;
Security&lt;BR /&gt;
System&lt;BR /&gt;
Hardware Events&lt;BR /&gt;
Internet Explorer&lt;BR /&gt;
Key Management Service&lt;BR /&gt;
MSExchange Management&lt;BR /&gt;
Windows Powershell&lt;/P&gt;

&lt;P&gt;I was poking around and edited /etc/apps/launcher/local/wmi.conf and added:&lt;/P&gt;

&lt;P&gt;[WMI:Event Log: Print Servers]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
index = default&lt;BR /&gt;
interval = 5&lt;BR /&gt;
server = servername&lt;BR /&gt;
event_log_file = Microsoft-Windows-PrintService/Operational&lt;/P&gt;

&lt;P&gt;This adds to the Remote Event Log Collections but it still doesn't pull anything.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:52:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77640#M15894</guid>
      <dc:creator>corommendoza</dc:creator>
      <dc:date>2020-09-28T14:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft-Windows-PrintService/Operational Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77641#M15895</link>
      <description>&lt;P&gt;Try removing the spaces from [WMI:EventLog:PrintServers]&lt;BR /&gt;
After you enable the WMI input, check the splunkd.log for errors.  It may take a few minutes before it actually starts pulling data.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2013 16:13:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77641#M15895</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-10-01T16:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft-Windows-PrintService/Operational Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77642#M15896</link>
      <description>&lt;P&gt;Removed spaces and this is what I get in the log:&lt;/P&gt;

&lt;P&gt;10-01-2013 11:22:12.990 -0700 INFO  WinEventLogInputProcessor - main-thread: Processing existing Windows Event Log 'Microsoft-Windows-PrintService/Operational'&lt;BR /&gt;
10-01-2013 11:22:12.990 -0700 INFO  WinEventLogInputProcessor - main-thread: Finished processing existing Windows Event Log 'Microsoft-Windows-PrintService/Operational': total_events='0' with empty_msg='0'.&lt;/P&gt;

&lt;P&gt;I checked server and I can see events in that log.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:52:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77642#M15896</guid>
      <dc:creator>corommendoza</dc:creator>
      <dc:date>2020-09-28T14:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft-Windows-PrintService/Operational Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77643#M15897</link>
      <description>&lt;P&gt;Have you searched the indexer for printserver?&lt;BR /&gt;&lt;BR /&gt;
If it could not find the log, then I'm pretty sure it would throw an error.&lt;BR /&gt;&lt;BR /&gt;
You might want to give it some time.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2013 18:50:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77643#M15897</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-10-01T18:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft-Windows-PrintService/Operational Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77644#M15898</link>
      <description>&lt;P&gt;I'll give it a few hours. I appreciate you helping me out with this luke.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2013 18:52:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77644#M15898</guid>
      <dc:creator>corommendoza</dc:creator>
      <dc:date>2013-10-01T18:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft-Windows-PrintService/Operational Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77645#M15899</link>
      <description>&lt;P&gt;No success. I guess no one has gotten it to work this way.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2013 18:43:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77645#M15899</guid>
      <dc:creator>corommendoza</dc:creator>
      <dc:date>2013-10-02T18:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft-Windows-PrintService/Operational Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77646#M15900</link>
      <description>&lt;P&gt;I know you said you don't want to load the universal forwarder, but it is the easiest way to get this done. In my local\inputs.conf I have the following indexed into an index called printlog and it works flawlessly.&lt;/P&gt;

&lt;P&gt;[WinEventLog:Microsoft-Windows-PrintService/Operational]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
index = printlog&lt;/P&gt;

&lt;P&gt;[WinEventLog:Microsoft-Windows-PrintService/Admin]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
index = printlog&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2013 01:18:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77646#M15900</guid>
      <dc:creator>antlefebvre</dc:creator>
      <dc:date>2013-10-10T01:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft-Windows-PrintService/Operational Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77647#M15901</link>
      <description>&lt;P&gt;I found answer from &lt;A href="http://forums.iis.net/p/1170786/1954080.aspx" target="_blank"&gt;http://forums.iis.net/p/1170786/1954080.aspx&lt;/A&gt; created on source machine a register "Key" at&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Microsoft-Windows-PrintService/Operational&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;and everything worked properly. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:34:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/77647#M15901</guid>
      <dc:creator>PaVedme</dc:creator>
      <dc:date>2020-09-29T09:34:52Z</dc:date>
    </item>
  </channel>
</rss>

