<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows host and source types not shown in search in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-host-and-source-types-not-shown-in-search/m-p/167612#M33934</link>
    <description>&lt;P&gt;Ok I got it I think. &lt;BR /&gt;
I copied authorize.conf from /etc/system/default to /etc/system/local on splunk light server and changed this line &lt;BR /&gt;
srchIndexesDefault = main;os &lt;BR /&gt;
to &lt;BR /&gt;
srchIndexesDefault = wineventlog;main;os &lt;BR /&gt;
for admin user. &lt;BR /&gt;
After restart everything worked as it should.&lt;BR /&gt;
I think there might be a bug in Windows Add-On not configuring correctly.&lt;/P&gt;</description>
    <pubDate>Sun, 21 Jun 2015 14:03:16 GMT</pubDate>
    <dc:creator>thejohn</dc:creator>
    <dc:date>2015-06-21T14:03:16Z</dc:date>
    <item>
      <title>Windows host and source types not shown in search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-host-and-source-types-not-shown-in-search/m-p/167608#M33930</link>
      <description>&lt;P&gt;I had to reinstall my universal forwarder on windows server and splunk stopped showing new messages. So deleted all messages of this host then I cleaned wineventlog index then reinstalled UF again because I thought that might force it. Now I don't see my server in hosts and all EventLog source types disappeared but when I search "index=wineventlog" I can see all new messages.&lt;/P&gt;

&lt;P&gt;How can I re-add the server to hosts and how to old source types?&lt;/P&gt;

&lt;P&gt;This is splunk light btw.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2015 15:20:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-host-and-source-types-not-shown-in-search/m-p/167608#M33930</guid>
      <dc:creator>thejohn</dc:creator>
      <dc:date>2015-06-19T15:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: Windows host and source types not shown in search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-host-and-source-types-not-shown-in-search/m-p/167609#M33931</link>
      <description>&lt;P&gt;I restored splunk to snapshot just after install and repeated the installation of UF multiple times. First I specified only receiving server and again all logs went to wineventlog index but are not shown anywhere. Second I tried configuring UF as deployment client and server does not receive any messages. I am totally lost... &lt;/P&gt;</description>
      <pubDate>Sat, 20 Jun 2015 00:11:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-host-and-source-types-not-shown-in-search/m-p/167609#M33931</guid>
      <dc:creator>thejohn</dc:creator>
      <dc:date>2015-06-20T00:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: Windows host and source types not shown in search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-host-and-source-types-not-shown-in-search/m-p/167610#M33932</link>
      <description>&lt;P&gt;I am having the same issue here too... all my linux host are showing.  WinSrv 2012 showing but now win7.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jun 2015 00:44:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-host-and-source-types-not-shown-in-search/m-p/167610#M33932</guid>
      <dc:creator>pierre31</dc:creator>
      <dc:date>2015-06-20T00:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: Windows host and source types not shown in search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-host-and-source-types-not-shown-in-search/m-p/167611#M33933</link>
      <description>&lt;P&gt;Ok so I think I know what the problem is. By default splunk searches only main index I think. Windows Add-On uses wineventlog which is not searched. I set it up again so forwarder forwards to main index instead of wineventlog and success, the host and sourcetypes were shown. So now the question is how do I configure splunk light to also search wineventlog index. If you use splunk enterprise I think you just need to set up roles so that it is visible by your user. Don't know how to do this on light yet...&lt;/P&gt;

&lt;P&gt;edit:&lt;BR /&gt;
Also when I configured UF as deployment client I thought it will forward messages on its own, but it turns out you still need to add receiving server.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jun 2015 13:26:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-host-and-source-types-not-shown-in-search/m-p/167611#M33933</guid>
      <dc:creator>thejohn</dc:creator>
      <dc:date>2015-06-21T13:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: Windows host and source types not shown in search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-host-and-source-types-not-shown-in-search/m-p/167612#M33934</link>
      <description>&lt;P&gt;Ok I got it I think. &lt;BR /&gt;
I copied authorize.conf from /etc/system/default to /etc/system/local on splunk light server and changed this line &lt;BR /&gt;
srchIndexesDefault = main;os &lt;BR /&gt;
to &lt;BR /&gt;
srchIndexesDefault = wineventlog;main;os &lt;BR /&gt;
for admin user. &lt;BR /&gt;
After restart everything worked as it should.&lt;BR /&gt;
I think there might be a bug in Windows Add-On not configuring correctly.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jun 2015 14:03:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-host-and-source-types-not-shown-in-search/m-p/167612#M33934</guid>
      <dc:creator>thejohn</dc:creator>
      <dc:date>2015-06-21T14:03:16Z</dc:date>
    </item>
  </channel>
</rss>

