<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Some Local Windows Eventlogs not being indexed in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Some-Local-Windows-Eventlogs-not-being-indexed/m-p/17926#M2398</link>
    <description>&lt;P&gt;I am trying to index the local windows eventlogs, but there appears to be an issue reading the "Security" eventlog, and is then no longer indexing all the logs ongoing. On restart of splunk the logs are being processed alphabetically, with a Processing event then a Finished event.  It appears the Security log gets a Processing event, but not a Finished event.&lt;/P&gt;

&lt;P&gt;I have cleared the Security Log (and other logs aswell), but the issue persists.&lt;/P&gt;

&lt;P&gt;Has anyone else seen this issue?&lt;/P&gt;

&lt;P&gt;\var\log\splunk\splunkd.log  - Splunk 4.3.2 on Windows&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;10-31-2012 12:19:20.240 +1100 INFO  WinEventLogInputProcessor - main-thread: Processing existing Windows Event Log 'Security'&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;10-31-2012 12:18:59.194 +1100 INFO  WinEventLogInputProcessor - main-thread: Finished processing existing Windows Event Log 'Internet Explorer': total_events='0' with empty_msg='0'.&lt;/P&gt;

&lt;P&gt;10-31-2012 12:18:59.194 +1100 INFO  WinEventLogInputProcessor - main-thread: Processing existing Windows Event Log 'Internet Explorer'&lt;/P&gt;

&lt;P&gt;10-31-2012 12:18:59.194 +1100 INFO  WinEventLogInputProcessor - main-thread: Finished processing existing Windows Event Log 'HardwareEvents': total_events='0' with empty_msg='0'.&lt;/P&gt;

&lt;P&gt;10-31-2012 12:18:59.194 +1100 INFO  WinEventLogInputProcessor - main-thread: Processing existing Windows Event Log 'HardwareEvents'&lt;/P&gt;

&lt;P&gt;10-31-2012 12:18:59.194 +1100 INFO  WinEventLogInputProcessor - main-thread: Finished processing existing Windows Event Log 'ForwardedEvents': total_events='249' with empty_msg='0'.&lt;/P&gt;

&lt;P&gt;10-31-2012 12:18:58.367 +1100 INFO  WinEventLogInputProcessor - main-thread: Processing existing Windows Event Log 'ForwardedEvents'&lt;/P&gt;

&lt;P&gt;10-31-2012 12:18:58.367 +1100 INFO  WinEventLogInputProcessor - main-thread: Finished processing existing Windows Event Log 'Application': total_events='0' with empty_msg='0'.&lt;/P&gt;

&lt;P&gt;10-31-2012 12:18:58.367 +1100 INFO  WinEventLogInputProcessor - main-thread: Processing existing Windows Event Log 'Application'&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 12:42:59 GMT</pubDate>
    <dc:creator>marcpatron</dc:creator>
    <dc:date>2020-09-28T12:42:59Z</dc:date>
    <item>
      <title>Some Local Windows Eventlogs not being indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Some-Local-Windows-Eventlogs-not-being-indexed/m-p/17926#M2398</link>
      <description>&lt;P&gt;I am trying to index the local windows eventlogs, but there appears to be an issue reading the "Security" eventlog, and is then no longer indexing all the logs ongoing. On restart of splunk the logs are being processed alphabetically, with a Processing event then a Finished event.  It appears the Security log gets a Processing event, but not a Finished event.&lt;/P&gt;

&lt;P&gt;I have cleared the Security Log (and other logs aswell), but the issue persists.&lt;/P&gt;

&lt;P&gt;Has anyone else seen this issue?&lt;/P&gt;

&lt;P&gt;\var\log\splunk\splunkd.log  - Splunk 4.3.2 on Windows&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;10-31-2012 12:19:20.240 +1100 INFO  WinEventLogInputProcessor - main-thread: Processing existing Windows Event Log 'Security'&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;10-31-2012 12:18:59.194 +1100 INFO  WinEventLogInputProcessor - main-thread: Finished processing existing Windows Event Log 'Internet Explorer': total_events='0' with empty_msg='0'.&lt;/P&gt;

&lt;P&gt;10-31-2012 12:18:59.194 +1100 INFO  WinEventLogInputProcessor - main-thread: Processing existing Windows Event Log 'Internet Explorer'&lt;/P&gt;

&lt;P&gt;10-31-2012 12:18:59.194 +1100 INFO  WinEventLogInputProcessor - main-thread: Finished processing existing Windows Event Log 'HardwareEvents': total_events='0' with empty_msg='0'.&lt;/P&gt;

&lt;P&gt;10-31-2012 12:18:59.194 +1100 INFO  WinEventLogInputProcessor - main-thread: Processing existing Windows Event Log 'HardwareEvents'&lt;/P&gt;

&lt;P&gt;10-31-2012 12:18:59.194 +1100 INFO  WinEventLogInputProcessor - main-thread: Finished processing existing Windows Event Log 'ForwardedEvents': total_events='249' with empty_msg='0'.&lt;/P&gt;

&lt;P&gt;10-31-2012 12:18:58.367 +1100 INFO  WinEventLogInputProcessor - main-thread: Processing existing Windows Event Log 'ForwardedEvents'&lt;/P&gt;

&lt;P&gt;10-31-2012 12:18:58.367 +1100 INFO  WinEventLogInputProcessor - main-thread: Finished processing existing Windows Event Log 'Application': total_events='0' with empty_msg='0'.&lt;/P&gt;

&lt;P&gt;10-31-2012 12:18:58.367 +1100 INFO  WinEventLogInputProcessor - main-thread: Processing existing Windows Event Log 'Application'&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:42:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Some-Local-Windows-Eventlogs-not-being-indexed/m-p/17926#M2398</guid>
      <dc:creator>marcpatron</dc:creator>
      <dc:date>2020-09-28T12:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Some Local Windows Eventlogs not being indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Some-Local-Windows-Eventlogs-not-being-indexed/m-p/17927#M2399</link>
      <description>&lt;P&gt;can you please clarify your scenario? Are you indexing evtx logs by pointing Splunk to the directory?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2012 03:59:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Some-Local-Windows-Eventlogs-not-being-indexed/m-p/17927#M2399</guid>
      <dc:creator>rovechkin_splun</dc:creator>
      <dc:date>2012-10-31T03:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: Some Local Windows Eventlogs not being indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Some-Local-Windows-Eventlogs-not-being-indexed/m-p/17928#M2400</link>
      <description>&lt;P&gt;I am indexing using Local Event Log collection, configured in the Windows App, not via monitoring the .evtx files. The server is Win2008.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2012 04:06:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Some-Local-Windows-Eventlogs-not-being-indexed/m-p/17928#M2400</guid>
      <dc:creator>marcpatron</dc:creator>
      <dc:date>2012-10-31T04:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Some Local Windows Eventlogs not being indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Some-Local-Windows-Eventlogs-not-being-indexed/m-p/17929#M2401</link>
      <description>&lt;P&gt;The problem has been solved.&lt;/P&gt;

&lt;P&gt;At the same time of a bunch of other changes, some firewall rules were put in place around the Splunk server. The WinEventLog:Security input by default looks up AD to resolve SID's in events (evt_resolve_ad_obj = 1). This uses RPC ports to communicate to the AD servers. I have disabled this setting (evt_resolve_ad_obj = 0) and all event logs are now being indexed once again. There appears to be no issue with resolved usernames in the eventlogs.&lt;/P&gt;

&lt;P&gt;I discovered this in the splunkd.log with DEBUG turned on for WinEventLog*. Initially the following entries appear just as the Security log was begining to be processed:&lt;/P&gt;

&lt;P&gt;WinEventLogChannel - EvtDC::bind: Found DC='\SERVER1.xyz.loc', DCsite='XYZ', ClientSite = 'XYZ', Domain='xyz.loc'&lt;BR /&gt;
WinEventLogChannel - connectToDC: DsBind failed: (1722)'The operation completed successfully.'&lt;BR /&gt;
WinEventLogChannel - init: Failed to bind to DC, dc_bind_time=21140 msec&lt;/P&gt;

&lt;P&gt;Then every 21 seconds:&lt;/P&gt;

&lt;P&gt;WinEventLogChannel - connectToDC: DsBind failed: (1722)'The operation completed successfully.'&lt;BR /&gt;
WinEventLogChannel - WinEventLogChannel::translateSidLocally Translating sids locally...&lt;/P&gt;

&lt;P&gt;I assume that the events were being indexed, just very slowly, so that it would appear to never finish indexing the security log and move onto other logs.&lt;/P&gt;

&lt;P&gt;I have reviewed the firewall rules and need to allow the blocked RPC port (tcp/1026).&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:50:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Some-Local-Windows-Eventlogs-not-being-indexed/m-p/17929#M2401</guid>
      <dc:creator>marcpatron</dc:creator>
      <dc:date>2020-09-28T12:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: Some Local Windows Eventlogs not being indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Some-Local-Windows-Eventlogs-not-being-indexed/m-p/17930#M2402</link>
      <description>&lt;P&gt;Also see this Answers thread:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/75970/forwarder-shows-extreme-lag-or-latency-when-sending-windows-security-eventlog-data"&gt;http://splunk-base.splunk.com/answers/75970/forwarder-shows-extreme-lag-or-latency-when-sending-windows-security-eventlog-data&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2013 17:47:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Some-Local-Windows-Eventlogs-not-being-indexed/m-p/17930#M2402</guid>
      <dc:creator>splunkIT</dc:creator>
      <dc:date>2013-03-13T17:47:56Z</dc:date>
    </item>
  </channel>
</rss>

