<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I receiving no WinEventlog:Security events from the universal-forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148294#M30160</link>
    <description>&lt;P&gt;I am receiving Security events from the Indexer which I use a Universal forwarder to send events to itself instead of point to the files.  I am  still not seeing Security events from the standalone Windows2008R2 Server. As before I am still getting the setup event, performance events but no security events.&lt;/P&gt;

&lt;P&gt;Is a trusted certificate required for this transaction? I did not configure that part of the Universal Forwarder.&lt;/P&gt;</description>
    <pubDate>Sat, 21 Feb 2015 17:09:35 GMT</pubDate>
    <dc:creator>mark320i</dc:creator>
    <dc:date>2015-02-21T17:09:35Z</dc:date>
    <item>
      <title>Why am I receiving no WinEventlog:Security events from the universal-forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148290#M30156</link>
      <description>&lt;P&gt;I am new to Splunk trying to fill in for someone that has left the company and the company could not afford to continue service this time around.&lt;/P&gt;

&lt;P&gt;I am trying to read Event ID 4625 and 4624.  What I am noticing is that I am getting NO Security events.  I do however receive Setup events.  I am using the Universal Forwarder to get events from Windows 7 and Server 2008 R2 machines. At home I am using Workgroup and at Work a Domain, same results on both.&lt;/P&gt;

&lt;P&gt;As for the search I enter the following:  &lt;CODE&gt;sourcetype=WinEventLog:S*&lt;/CODE&gt;&lt;BR /&gt;
I also enter in &lt;CODE&gt;4625* OR 4624*&lt;/CODE&gt; &lt;BR /&gt;
I can view the events via the Event View so I know the machine in question has the events. Just need to track to see if it is leaving the target machine and going to the indexer and then if the indexer is for some reason filtering the events.  &lt;/P&gt;

&lt;P&gt;Splunk version 6.0.182037&lt;BR /&gt;
Splunk Universal Forwarder 6.2.1-245427&lt;/P&gt;

&lt;P&gt;Any help or pointing to docs would be helpful. I have been reading a lot of the posts trying things, but nothing seems to help and I am running out of time!!&lt;/P&gt;

&lt;P&gt;Thanks in Advance.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Feb 2015 15:18:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148290#M30156</guid>
      <dc:creator>mark320i</dc:creator>
      <dc:date>2015-02-21T15:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I receiving no WinEventlog:Security events from the universal-forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148291#M30157</link>
      <description>&lt;P&gt;Does you inputs.conf have &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog://Security]
index = indexname
disabled = 0 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;if not add that in and restart the forwarder service. &lt;/P&gt;</description>
      <pubDate>Sat, 21 Feb 2015 15:30:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148291#M30157</guid>
      <dc:creator>ulikabbq</dc:creator>
      <dc:date>2015-02-21T15:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I receiving no WinEventlog:Security events from the universal-forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148292#M30158</link>
      <description>&lt;P&gt;Thanks for the response!!&lt;BR /&gt;
I am assuming that I am adding this to the Universal forwarder inputs.conf file?    I did go ahead and add the text and have restarted twice.  I had a similar statement but disabled = false previously. Still no success.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Feb 2015 15:52:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148292#M30158</guid>
      <dc:creator>mark320i</dc:creator>
      <dc:date>2015-02-21T15:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I receiving no WinEventlog:Security events from the universal-forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148293#M30159</link>
      <description>&lt;P&gt;I just received this error message on the indexer.  &lt;/P&gt;

&lt;P&gt;received event for unconfigured/disabled/deleted index='indexname' with source='source::WinEventLog:Security' host='host::ASUS' sourcetype='sourcetype::WinEventLog:Security' (2 missing total) &lt;/P&gt;</description>
      <pubDate>Sat, 21 Feb 2015 15:55:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148293#M30159</guid>
      <dc:creator>mark320i</dc:creator>
      <dc:date>2015-02-21T15:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I receiving no WinEventlog:Security events from the universal-forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148294#M30160</link>
      <description>&lt;P&gt;I am receiving Security events from the Indexer which I use a Universal forwarder to send events to itself instead of point to the files.  I am  still not seeing Security events from the standalone Windows2008R2 Server. As before I am still getting the setup event, performance events but no security events.&lt;/P&gt;

&lt;P&gt;Is a trusted certificate required for this transaction? I did not configure that part of the Universal Forwarder.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Feb 2015 17:09:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148294#M30160</guid>
      <dc:creator>mark320i</dc:creator>
      <dc:date>2015-02-21T17:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I receiving no WinEventlog:Security events from the universal-forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148295#M30161</link>
      <description>&lt;P&gt;set the index name to an index that exists on your system. you can set it to 'main' if you want it in the main index&lt;/P&gt;</description>
      <pubDate>Sat, 21 Feb 2015 17:32:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148295#M30161</guid>
      <dc:creator>ulikabbq</dc:creator>
      <dc:date>2015-02-21T17:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I receiving no WinEventlog:Security events from the universal-forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148296#M30162</link>
      <description>&lt;P&gt;First THANKS!!!!&lt;BR /&gt;&lt;BR /&gt;
where is this documented in the Splunk manuals???&lt;/P&gt;</description>
      <pubDate>Sat, 21 Feb 2015 17:52:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148296#M30162</guid>
      <dc:creator>mark320i</dc:creator>
      <dc:date>2015-02-21T17:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I receiving no WinEventlog:Security events from the universal-forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148297#M30163</link>
      <description>&lt;P&gt;I did find reference to this in the inputs.conf edit doc, what is interesting is this seems to be a default setting. Do you know why it did not work?    Is this an issue with Splunk or the OS that requires it to be specifically listed? &lt;/P&gt;</description>
      <pubDate>Sat, 21 Feb 2015 18:12:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148297#M30163</guid>
      <dc:creator>mark320i</dc:creator>
      <dc:date>2015-02-21T18:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I receiving no WinEventlog:Security events from the universal-forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148298#M30164</link>
      <description>&lt;P&gt;I think it would only be a default setting if you selected it during the installation of the forwarder. Most people leave those things undefined and manually configure the inputs.conf. &lt;/P&gt;</description>
      <pubDate>Sat, 21 Feb 2015 19:20:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-receiving-no-WinEventlog-Security-events-from-the/m-p/148298#M30164</guid>
      <dc:creator>ulikabbq</dc:creator>
      <dc:date>2015-02-21T19:20:43Z</dc:date>
    </item>
  </channel>
</rss>

