<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I not seeing any Windows security event logs after installing a universal forwarder on a remote Windows server? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116529#M24315</link>
    <description>&lt;P&gt;Ya, that message needs to be more prominent during the UF install -- that this needs to be done. This is going to burn a lot of people...&lt;/P&gt;</description>
    <pubDate>Thu, 08 Sep 2016 16:31:45 GMT</pubDate>
    <dc:creator>Michael</dc:creator>
    <dc:date>2016-09-08T16:31:45Z</dc:date>
    <item>
      <title>Why am I not seeing any Windows security event logs after installing a universal forwarder on a remote Windows server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116519#M24305</link>
      <description>&lt;P&gt;I have a new standalone Splunk install that I want to test. It's installed on Windows.&lt;/P&gt;

&lt;P&gt;I want to monitor the Windows Security event log of a remote Windows Server. I have installed the UF on this server.&lt;/P&gt;

&lt;P&gt;There is a connection between the remote Windows server and the Splunk server, so that eliminates firewall and networking problems.&lt;/P&gt;

&lt;P&gt;I am not seeing the Windows Security events on the Splunk server however.&lt;/P&gt;

&lt;P&gt;What am I missing?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Nov 2014 02:24:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116519#M24305</guid>
      <dc:creator>GLCFSCS</dc:creator>
      <dc:date>2014-11-13T02:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing any Windows security event logs after installing a universal forwarder on a remote Windows server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116520#M24306</link>
      <description>&lt;P&gt;Addinitial info ... I get this error in Splunk:&lt;/P&gt;

&lt;P&gt;received event for unconfigured/disabled/deleted index='wineventlog' with source='source::WinEventLog:Security' host='host::SERVER01' sourcetype='sourcetype::WinEventLog:Security' (1 missing total)&lt;/P&gt;</description>
      <pubDate>Thu, 13 Nov 2014 03:23:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116520#M24306</guid>
      <dc:creator>GLCFSCS</dc:creator>
      <dc:date>2014-11-13T03:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing any Windows security event logs after installing a universal forwarder on a remote Windows server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116521#M24307</link>
      <description>&lt;P&gt;On the UF make sure the Windows app has security event logs enabled in inputs.conf. Check to ensure output.conf is configured to send logs to your Splunk server. &lt;/P&gt;

&lt;P&gt;On the Splunk server make sure your inputs.conf is configured to listen on 9997 (or your configured port). Make sure indexes.conf is configured with an index for security events. You'll need to create an index called msad unless you've selected another index on the UF. &lt;/P&gt;

&lt;P&gt;Check splunkd.log for errors. Use netstat to see if the UF is sending/established on TCP 9997 and if the Splunk server is listening on tcp 9997. Even though you said they had a direct connection, make sure the windows firewall isn't blocking outbound ports from the UF and that the Splunk server is not being blocked inbound. &lt;/P&gt;

&lt;P&gt;Between the conf files, netstat, firewalls, and log files you should see something. Also, try an obligatory UF service restart. &lt;/P&gt;

&lt;P&gt;Let us know if any of these steps help. &lt;/P&gt;</description>
      <pubDate>Thu, 13 Nov 2014 03:30:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116521#M24307</guid>
      <dc:creator>s72ucor</dc:creator>
      <dc:date>2014-11-13T03:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing any Windows security event logs after installing a universal forwarder on a remote Windows server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116522#M24308</link>
      <description>&lt;P&gt;Did you create that index on your Splunk server?  &lt;/P&gt;

&lt;P&gt;That error means that it tried to write to an index that isn't there. &lt;/P&gt;

&lt;P&gt;Create the index and the events should go away. &lt;/P&gt;</description>
      <pubDate>Thu, 13 Nov 2014 03:33:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116522#M24308</guid>
      <dc:creator>s72ucor</dc:creator>
      <dc:date>2014-11-13T03:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing any Windows security event logs after installing a universal forwarder on a remote Windows server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116523#M24309</link>
      <description>&lt;P&gt;s/events/errors/&lt;/P&gt;</description>
      <pubDate>Thu, 13 Nov 2014 03:34:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116523#M24309</guid>
      <dc:creator>s72ucor</dc:creator>
      <dc:date>2014-11-13T03:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing any Windows security event logs after installing a universal forwarder on a remote Windows server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116524#M24310</link>
      <description>&lt;P&gt;OK, I created the index "wineventlog" and it's working.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Nov 2014 03:39:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116524#M24310</guid>
      <dc:creator>GLCFSCS</dc:creator>
      <dc:date>2014-11-13T03:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing any Windows security event logs after installing a universal forwarder on a remote Windows server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116525#M24311</link>
      <description>&lt;P&gt;Make sure your Indexers also have the Splunk App for Windows Infrastructure app and windows add-on installed. If the Indexers don't have the apps and related add-on you won't see any event data.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 19:30:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116525#M24311</guid>
      <dc:creator>scc00</dc:creator>
      <dc:date>2016-01-20T19:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing any Windows security event logs after installing a universal forwarder on a remote Windows server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116526#M24312</link>
      <description>&lt;P&gt;I have a similar problem. I installed the UF, but the inputs.conf did NOT including the system, apps, or security events even though I selected them during install. I manually added, restarted. Confirmed forward destination is correct (outputs.conf).&lt;/P&gt;

&lt;P&gt;Something you can test is make sure the networking (firewalls) are all OK with "netstat -an" to confirm they are communicating. This is almost always the problem (but not in this time...).&lt;/P&gt;

&lt;P&gt;In my case, they are communicating, but no events are being forwarded even though they are being generated (confirmed with local Event Viewer).&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 16:22:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116526#M24312</guid>
      <dc:creator>Michael</dc:creator>
      <dc:date>2016-08-16T16:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing any Windows security event logs after installing a universal forwarder on a remote Windows server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116527#M24313</link>
      <description>&lt;P&gt;Hi, I am also having same problem as Michael. Splunk installed on Linux host taking in syslog no problem. Two UF installed on two Windows2012R2 hosts, not sending windows event logs despite selecting them during UF install. Any ideas? Thanks,Hi, having exact same problem as Michael. I am new to Splunk and am reading as much as I can but would appreciate a point in the right direction to sort this out. I have Splunk Enterprise installed on a Linux host and working correctly taking in syslog. I have two universal forwarders installed on Windows 2012R2 hosts, one has IIS on and is sending the logs to the indexer correctly. Just no Windows Event Logs &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Chris&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 08 Sep 2016 15:25:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116527#M24313</guid>
      <dc:creator>chrisdavies76</dc:creator>
      <dc:date>2016-09-08T15:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing any Windows security event logs after installing a universal forwarder on a remote Windows server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116528#M24314</link>
      <description>&lt;P&gt;In my case, I followed the answer below and created the said index (wineventlog) and it worked.&lt;/P&gt;

&lt;P&gt;Discovered this is default with the UF on Windows systems that it sends to this directory, not "main". I'm sure it says as much during the installation, but I must have missed it -- if not, it should be...&lt;/P&gt;

&lt;P&gt;Apologies; not much to offer (yet) on the Linux issue (SELinux?). Although, this has always been a firewall issue for me on 'nix in the past...&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2016 16:30:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116528#M24314</guid>
      <dc:creator>Michael</dc:creator>
      <dc:date>2016-09-08T16:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing any Windows security event logs after installing a universal forwarder on a remote Windows server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116529#M24315</link>
      <description>&lt;P&gt;Ya, that message needs to be more prominent during the UF install -- that this needs to be done. This is going to burn a lot of people...&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2016 16:31:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-any-Windows-security-event-logs-after/m-p/116529#M24315</guid>
      <dc:creator>Michael</dc:creator>
      <dc:date>2016-09-08T16:31:45Z</dc:date>
    </item>
  </channel>
</rss>

