<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Application and Services Event Logs not appearing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Application-and-Services-Event-Logs-not-appearing/m-p/82141#M16969</link>
    <description>&lt;P&gt;To be sure I would change your stanzas to use &lt;CODE&gt;WinEventLog&lt;/CODE&gt; instead of &lt;CODE&gt;winEventLog&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;I would then look at the following documentation, as you may need to include the full path the event log:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.3/Data/MonitorWindowsdata#Event_log_monitor_configuration_values"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.3/Data/MonitorWindowsdata#Event_log_monitor_configuration_values&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I also assume you search starts with:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=wineventlog
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jul 2013 16:13:43 GMT</pubDate>
    <dc:creator>MHibbin</dc:creator>
    <dc:date>2013-07-02T16:13:43Z</dc:date>
    <item>
      <title>Application and Services Event Logs not appearing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Application-and-Services-Event-Logs-not-appearing/m-p/82140#M16968</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We are trying to setup Splunk to monitor custom application event logs that are already added to the event viewer. Here is an example of the inputs.conf example we are using and we are running the service as system. Any ideas why it is not collecting these event logs?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[winEventLog:DBMApplicationEventLog]
disabled = 0
index = wineventlog
current_only = 1

[winEventLog:DBMBusinessEventLog]
disabled = 0
index = wineventlog
current_only = 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/2013-07-02_1135.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2013 15:40:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Application-and-Services-Event-Logs-not-appearing/m-p/82140#M16968</guid>
      <dc:creator>aaronkorn</dc:creator>
      <dc:date>2013-07-02T15:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Application and Services Event Logs not appearing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Application-and-Services-Event-Logs-not-appearing/m-p/82141#M16969</link>
      <description>&lt;P&gt;To be sure I would change your stanzas to use &lt;CODE&gt;WinEventLog&lt;/CODE&gt; instead of &lt;CODE&gt;winEventLog&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;I would then look at the following documentation, as you may need to include the full path the event log:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.3/Data/MonitorWindowsdata#Event_log_monitor_configuration_values"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.3/Data/MonitorWindowsdata#Event_log_monitor_configuration_values&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I also assume you search starts with:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=wineventlog
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2013 16:13:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Application-and-Services-Event-Logs-not-appearing/m-p/82141#M16969</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2013-07-02T16:13:43Z</dc:date>
    </item>
  </channel>
</rss>

