<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: forward from windows machine problem in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/forward-from-windows-machine-problem/m-p/108785#M22884</link>
    <description>&lt;P&gt;I commented on another thread as well:&lt;/P&gt;

&lt;P&gt;I'm seeing the same issue. I believe it is because if you look at the default config files in both the App and the Windows TA add-ons, the indexes are NOT the same. The Win Infra App looks for windows event logs in an index named "winevents" while the TA-Add-On saves event logs to index "wineventlog". I'm not sure how the Infra App config file could possibly work since it doesn't even look in the same locations". I'm working on trying to fix all of those mis-matches myself.  Looking at the default eventtypes in the Infra App and the TA-Add-On, they're not the same either.......ugh.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Sep 2014 22:40:24 GMT</pubDate>
    <dc:creator>ldgrube</dc:creator>
    <dc:date>2014-09-16T22:40:24Z</dc:date>
    <item>
      <title>forward from windows machine problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forward-from-windows-machine-problem/m-p/108780#M22879</link>
      <description>&lt;P&gt;I have installed a universial forwarder on a windows machine and having it send to my splunk machine. &lt;BR /&gt;
The problem is that on the windows app that i have installed on the splunk server. I cant see any events, in the search app i see it like this for exampel. Running 4.2 on the server.&lt;BR /&gt;
WinEventLog:System&lt;BR /&gt;&lt;BR /&gt;
WinEventLog:Setup&lt;BR /&gt;&lt;BR /&gt;
WinEventLog:Security&lt;BR /&gt;&lt;BR /&gt;
WinEventLog:Application &lt;BR /&gt;
Perfmon:Network Interface&lt;BR /&gt;&lt;BR /&gt;
Perfmon:Free Disk Space &lt;BR /&gt;
Perfmon:CPU Load&lt;BR /&gt;&lt;BR /&gt;
Perfmon:Available Memory&lt;BR /&gt;&lt;BR /&gt;
ActiveDirectory&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2011 11:45:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forward-from-windows-machine-problem/m-p/108780#M22879</guid>
      <dc:creator>fisk12</dc:creator>
      <dc:date>2011-05-25T11:45:30Z</dc:date>
    </item>
    <item>
      <title>Re: forward from windows machine problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forward-from-windows-machine-problem/m-p/108781#M22880</link>
      <description>&lt;P&gt;I have a few questions:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Is only this one machine forwarding events having the issue (can other machine forward events without problems)?&lt;/LI&gt;
&lt;LI&gt;Is the server setup to receive Splunk forwarded traffic?&lt;/LI&gt;
&lt;LI&gt;Is the forwarder sending to the same port the server is looking for (see question 3)?&lt;/LI&gt;
&lt;LI&gt;From the forwarder, can you telnet to the server over the listening port (telnet servername 8089)?&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 25 May 2011 12:02:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forward-from-windows-machine-problem/m-p/108781#M22880</guid>
      <dc:creator>treinke</dc:creator>
      <dc:date>2011-05-25T12:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: forward from windows machine problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forward-from-windows-machine-problem/m-p/108782#M22881</link>
      <description>&lt;P&gt;I may have been à bit unclear. The events are being forwarded. They just dont show up in the windows app.&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2011 12:28:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forward-from-windows-machine-problem/m-p/108782#M22881</guid>
      <dc:creator>fisk12</dc:creator>
      <dc:date>2011-05-25T12:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: forward from windows machine problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forward-from-windows-machine-problem/m-p/108783#M22882</link>
      <description>&lt;P&gt;Anyone? Sounds like quite an easy problem to solve.&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2011 19:22:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forward-from-windows-machine-problem/m-p/108783#M22882</guid>
      <dc:creator>fisk12</dc:creator>
      <dc:date>2011-05-30T19:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: forward from windows machine problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forward-from-windows-machine-problem/m-p/108784#M22883</link>
      <description>&lt;P&gt;I commented on another thread as well:&lt;/P&gt;

&lt;P&gt;I'm seeing the same issue. I believe it is because if you look at the default config files in both the App and the Windows TA add-ons, the indexes are NOT the same. The Win Infra App looks for windows event logs in an index named "winevents" while the TA-Add-On saves event logs to index "wineventlog". I'm not sure how the Infra App config file could possibly work since it doesn't even look in the same locations". I'm working on trying to fix all of those mis-matches myself.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2014 22:35:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forward-from-windows-machine-problem/m-p/108784#M22883</guid>
      <dc:creator>ldgrube</dc:creator>
      <dc:date>2014-09-16T22:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: forward from windows machine problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forward-from-windows-machine-problem/m-p/108785#M22884</link>
      <description>&lt;P&gt;I commented on another thread as well:&lt;/P&gt;

&lt;P&gt;I'm seeing the same issue. I believe it is because if you look at the default config files in both the App and the Windows TA add-ons, the indexes are NOT the same. The Win Infra App looks for windows event logs in an index named "winevents" while the TA-Add-On saves event logs to index "wineventlog". I'm not sure how the Infra App config file could possibly work since it doesn't even look in the same locations". I'm working on trying to fix all of those mis-matches myself.  Looking at the default eventtypes in the Infra App and the TA-Add-On, they're not the same either.......ugh.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2014 22:40:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forward-from-windows-machine-problem/m-p/108785#M22884</guid>
      <dc:creator>ldgrube</dc:creator>
      <dc:date>2014-09-16T22:40:24Z</dc:date>
    </item>
  </channel>
</rss>

