<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Universal Forwarder Not Forwarding Windows Event Logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Not-Forwarding-Windows-Event-Logs/m-p/95298#M19859</link>
    <description>&lt;P&gt;I have just installed a Universal forwarder on a windows server and during the installation I selected the option to index windows event logs and performance logs.  &lt;/P&gt;

&lt;P&gt;I have checked splunk and can see it indexing performance logs, however it is not indexing the windows event logs.  I can see these logs set-up in the following location.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\MSICreated\local\inputs.conf
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;As it is a windows server, do I need to copy in a windows folder where the inputs.conf file can be updated in &lt;CODE&gt;window\local&lt;/CODE&gt; folder &lt;/P&gt;</description>
    <pubDate>Thu, 20 Oct 2011 14:00:53 GMT</pubDate>
    <dc:creator>itsomana</dc:creator>
    <dc:date>2011-10-20T14:00:53Z</dc:date>
    <item>
      <title>Universal Forwarder Not Forwarding Windows Event Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Not-Forwarding-Windows-Event-Logs/m-p/95298#M19859</link>
      <description>&lt;P&gt;I have just installed a Universal forwarder on a windows server and during the installation I selected the option to index windows event logs and performance logs.  &lt;/P&gt;

&lt;P&gt;I have checked splunk and can see it indexing performance logs, however it is not indexing the windows event logs.  I can see these logs set-up in the following location.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\MSICreated\local\inputs.conf
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;As it is a windows server, do I need to copy in a windows folder where the inputs.conf file can be updated in &lt;CODE&gt;window\local&lt;/CODE&gt; folder &lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2011 14:00:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Not-Forwarding-Windows-Event-Logs/m-p/95298#M19859</guid>
      <dc:creator>itsomana</dc:creator>
      <dc:date>2011-10-20T14:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Not Forwarding Windows Event Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Not-Forwarding-Windows-Event-Logs/m-p/95299#M19860</link>
      <description>&lt;P&gt;No you shouldn't need to copy anything if the stanza's are properly enabled in the inputs.conf such as:&lt;/P&gt;

&lt;P&gt;[WinEventLog:Application]&lt;/P&gt;

&lt;P&gt;disabled = false&lt;/P&gt;

&lt;P&gt;[WinEventLog:Security]&lt;/P&gt;

&lt;P&gt;disabled = false&lt;/P&gt;

&lt;P&gt;[WinEventLog:System]&lt;/P&gt;

&lt;P&gt;disabled = false&lt;/P&gt;

&lt;P&gt;Have you viewed  the splunkd.log &lt;BR /&gt;
Open the %SPLUNK_HOME%\var\log\splunk\splunkd.log file and search for wmi or error . &lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2011 14:35:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Not-Forwarding-Windows-Event-Logs/m-p/95299#M19860</guid>
      <dc:creator>JSapienza</dc:creator>
      <dc:date>2011-10-20T14:35:42Z</dc:date>
    </item>
  </channel>
</rss>

