<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are my Windows Event Logs not being forwarded properly with an intermediate forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-my-Windows-Event-Logs-not-being-forwarded-properly-with/m-p/149001#M30342</link>
    <description>&lt;P&gt;It is a linux server that is acting as the receiver though.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Feb 2015 09:12:22 GMT</pubDate>
    <dc:creator>cchitten</dc:creator>
    <dc:date>2015-02-24T09:12:22Z</dc:date>
    <item>
      <title>Why are my Windows Event Logs not being forwarded properly with an intermediate forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-my-Windows-Event-Logs-not-being-forwarded-properly-with/m-p/148997#M30338</link>
      <description>&lt;P&gt;I am using an intermediary server (server 2) to collect forwarded logs from many servers (server 3,4,5,etc) and then I use a Splunk forwarder on there to forward those events to my full splunk instance server (server 1).&lt;/P&gt;

&lt;P&gt;However, my events are not being forwarded properly. On server 2 they look like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   [ Name]  Microsoft-Windows-Security-Auditing 
   [ Guid]  {*****************} 
   EventID 4769 
   Version 0 
   Level 0 
   Task 14337 
   Opcode 0 
   Keywords 0x6020000000000000 
  - TimeCreated
   [ SystemTime]  2015-02-23T14:17:22.10657400Z 
   EventRecordID 705673 
   Correlation 
  - Execution
   [ ProcessID]  568 
   [ ThreadID]  5524 
   Channel Security 
   Computer ****************
   Security 

  TargetUserName *********
  TargetDomainName ************
  ServiceName *********
  ServiceSid *********
  TicketOptions 0x40810345
  TicketEncryptionType 0x13
  IpAddress ***********
  IpPort ******** 
  Status 0x0 
  LogonGuid {************} 
  TransmittedServices - 

   [ Culture]  en-US 
   Message [*long message here*]
   Task Kerberos Service Ticket Operations 
   Opcode Info 
   Channel Security 
   Provider Microsoft Windows security auditing. 

   Keyword Audit Success 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But in splunk it just appears as this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;02/23/2015 02:08:40 PM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4769
EventType=0
Type=Microsoft Windows security auditing.
ComputerName=************
TaskCategory=Microsoft Windows security auditing.
OpCode=Microsoft Windows security auditing.
RecordNumber=705673
Keywords=Microsoft Windows security auditing.
Message=Microsoft Windows security auditing.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What could be happening in between that is affecting my event details?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Feb 2015 14:28:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-my-Windows-Event-Logs-not-being-forwarded-properly-with/m-p/148997#M30338</guid>
      <dc:creator>cchitten</dc:creator>
      <dc:date>2015-02-23T14:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Why are my Windows Event Logs not being forwarded properly with an intermediate forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-my-Windows-Event-Logs-not-being-forwarded-properly-with/m-p/148998#M30339</link>
      <description>&lt;P&gt;I have had the setup " a long time ago" .. and it work without this kind of problems at least ... have you done some changes on the windows collector side as how to process or maybe write/ save the events down on disk again ?Xml versus text or something ..&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2015 08:10:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-my-Windows-Event-Logs-not-being-forwarded-properly-with/m-p/148998#M30339</guid>
      <dc:creator>lmyrefelt</dc:creator>
      <dc:date>2015-02-24T08:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why are my Windows Event Logs not being forwarded properly with an intermediate forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-my-Windows-Event-Logs-not-being-forwarded-properly-with/m-p/148999#M30340</link>
      <description>&lt;P&gt;No. Just simply installed the splunk_TA_windows app onto my forwarder and that is what i got through.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:59:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-my-Windows-Event-Logs-not-being-forwarded-properly-with/m-p/148999#M30340</guid>
      <dc:creator>cchitten</dc:creator>
      <dc:date>2020-09-28T18:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why are my Windows Event Logs not being forwarded properly with an intermediate forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-my-Windows-Event-Logs-not-being-forwarded-properly-with/m-p/149000#M30341</link>
      <description>&lt;P&gt;aaah yeah, but you need to some configuration on the windows side to have another windows server act as a "event log receiver" . This is were some of the things might get screwed up "already"&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2015 08:39:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-my-Windows-Event-Logs-not-being-forwarded-properly-with/m-p/149000#M30341</guid>
      <dc:creator>lmyrefelt</dc:creator>
      <dc:date>2015-02-24T08:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why are my Windows Event Logs not being forwarded properly with an intermediate forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-my-Windows-Event-Logs-not-being-forwarded-properly-with/m-p/149001#M30342</link>
      <description>&lt;P&gt;It is a linux server that is acting as the receiver though.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2015 09:12:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-my-Windows-Event-Logs-not-being-forwarded-properly-with/m-p/149001#M30342</guid>
      <dc:creator>cchitten</dc:creator>
      <dc:date>2015-02-24T09:12:22Z</dc:date>
    </item>
  </channel>
</rss>

