<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UF on Server 2012 R2 Not Pulling in WinEventLog Application in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145616#M29675</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;
I think it is because of your syntax. Could you try the below?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog://Application]
disabled = 0
checkpointInterval = 5
current_only = 0
index = app
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
L&lt;/P&gt;</description>
    <pubDate>Tue, 30 Sep 2014 15:43:53 GMT</pubDate>
    <dc:creator>linu1988</dc:creator>
    <dc:date>2014-09-30T15:43:53Z</dc:date>
    <item>
      <title>UF on Server 2012 R2 Not Pulling in WinEventLog Application</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145614#M29673</link>
      <description>&lt;P&gt;This is the first time I have tried running a UF on a server 2012 R2 box.  Configuration is the same as my other win boxes.  Config being pushed out with deployment server.  However no wineventlogs are being sent.  UF is 6.1.2.  Config from deployment server:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog:Application]
checkpointInterval = 5
current_only = 0
disabled = false
index = app
start_from = oldest
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is this a bug?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 15:29:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145614#M29673</guid>
      <dc:creator>jodros</dc:creator>
      <dc:date>2014-09-30T15:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: UF on Server 2012 R2 Not Pulling in WinEventLog Application</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145615#M29674</link>
      <description>&lt;P&gt;The "5." by  index  is not in my config.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 15:33:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145615#M29674</guid>
      <dc:creator>jodros</dc:creator>
      <dc:date>2014-09-30T15:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: UF on Server 2012 R2 Not Pulling in WinEventLog Application</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145616#M29675</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I think it is because of your syntax. Could you try the below?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog://Application]
disabled = 0
checkpointInterval = 5
current_only = 0
index = app
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
L&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 15:43:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145616#M29675</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-09-30T15:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: UF on Server 2012 R2 Not Pulling in WinEventLog Application</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145617#M29676</link>
      <description>&lt;P&gt;That was my first thought.  However after reviewing I believe it is correct.  My ds is linux.   Verified that the config on the UF is [WinEventLog://Application].  I believe it gets translated.  Also, that config on the ds is working on all other winOS boxes.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 15:55:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145617#M29676</guid>
      <dc:creator>jodros</dc:creator>
      <dc:date>2014-09-30T15:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: UF on Server 2012 R2 Not Pulling in WinEventLog Application</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145618#M29677</link>
      <description>&lt;P&gt;Do you see any error? Is all the permissions given for reading the logs? Could you check if system/security logs work?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 16:07:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145618#M29677</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-09-30T16:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: UF on Server 2012 R2 Not Pulling in WinEventLog Application</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145619#M29678</link>
      <description>&lt;P&gt;Added Security logs to be monitored.  That works, however application logs are not working.  I added security log monitoring by using this configuration on the ds:&lt;/P&gt;

&lt;P&gt;[WinEventLog:Security]&lt;/P&gt;

&lt;P&gt;Which translated to&lt;/P&gt;

&lt;P&gt;[WinEventLog://Security]&lt;/P&gt;

&lt;P&gt;On the winOS box.  I don't know why application logs do not get indexed but security logs do?  There are no errors that I can see specific to this issue.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 17:01:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145619#M29678</guid>
      <dc:creator>jodros</dc:creator>
      <dc:date>2014-09-30T17:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: UF on Server 2012 R2 Not Pulling in WinEventLog Application</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145620#M29679</link>
      <description>&lt;P&gt;I also just upgraded the UF from 6.1.2 to 6.1.3.  Issues still persists.  I might try to install an older version of UF, possibly 5.x.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 17:27:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145620#M29679</guid>
      <dc:creator>jodros</dc:creator>
      <dc:date>2014-09-30T17:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: UF on Server 2012 R2 Not Pulling in WinEventLog Application</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145621#M29680</link>
      <description>&lt;P&gt;they won't support 2012 as per the versions. Newer version should work. Fire a support case. I will try on one of my VM tomorrow to see if it works&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 20:42:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145621#M29680</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-09-30T20:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: UF on Server 2012 R2 Not Pulling in WinEventLog Application</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145622#M29681</link>
      <description>&lt;P&gt;There was an existing props.conf entry on the indexers to drop wineventlog:application logs by default.  Removed and it is working with original syntax.  Sorry for the unneeded rabbit trail.  Thanks for your time.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 21:46:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-on-Server-2012-R2-Not-Pulling-in-WinEventLog-Application/m-p/145622#M29681</guid>
      <dc:creator>jodros</dc:creator>
      <dc:date>2014-09-30T21:46:52Z</dc:date>
    </item>
  </channel>
</rss>

