<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are Windows events logs no longer being forwarded after universal-forwarder upgrade to 6.1.2 for Windows 2008 R2? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-Windows-events-logs-no-longer-being-forwarded-after/m-p/173504#M34896</link>
    <description>&lt;P&gt;figured it out - forgot //&lt;/P&gt;

&lt;P&gt;[default]&lt;/P&gt;

&lt;P&gt;[WinEventLog://Application]&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
current_only = 1&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
index = tu_windows&lt;/P&gt;

&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
current_only = 1&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
blacklist = 5156|4656|33205|5158&lt;BR /&gt;
index = tu_windows&lt;/P&gt;

&lt;P&gt;[WinEventLog://System]&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
current_only = 1&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
index = tu_windows&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 18:36:18 GMT</pubDate>
    <dc:creator>ebailey</dc:creator>
    <dc:date>2020-09-28T18:36:18Z</dc:date>
    <item>
      <title>Why are Windows events logs no longer being forwarded after universal-forwarder upgrade to 6.1.2 for Windows 2008 R2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-Windows-events-logs-no-longer-being-forwarded-after/m-p/173503#M34895</link>
      <description>&lt;P&gt;We just upgraded a very old UF on Windows 2008 R2 to 6.1.2 None of the Windows event logs are being forwarded to the indexer though the UF logs and and custom application logs are being forwarded to the indexer so I know the UF can  forward data.&lt;/P&gt;

&lt;P&gt;The inputs.conf for the Windows Event logs&lt;/P&gt;

&lt;P&gt;[default]&lt;/P&gt;

&lt;P&gt;[WinEventLog:Application]&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
current_only = 1&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
index = test&lt;/P&gt;

&lt;P&gt;[WinEventLog:Security]&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
current_only = 1&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
blacklist = 5156|4656|33205|5158&lt;BR /&gt;
index = test&lt;/P&gt;

&lt;P&gt;[WinEventLog:System]&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
current_only = 1&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
index = test&lt;/P&gt;

&lt;P&gt;We have a lot of other UF installs that are using this inputs.conf so I am confused why this it not working.&lt;/P&gt;

&lt;P&gt;The only related message I am seeing is:&lt;/P&gt;

&lt;P&gt;INFO  ModularInputs - No stanzas found for scheme "WinEventLog" in inputs.conf at script (re)start.&lt;/P&gt;

&lt;P&gt;Any ideas why the inputs.conf is being ignored?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:34:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-Windows-events-logs-no-longer-being-forwarded-after/m-p/173503#M34895</guid>
      <dc:creator>ebailey</dc:creator>
      <dc:date>2020-09-28T18:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why are Windows events logs no longer being forwarded after universal-forwarder upgrade to 6.1.2 for Windows 2008 R2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-Windows-events-logs-no-longer-being-forwarded-after/m-p/173504#M34896</link>
      <description>&lt;P&gt;figured it out - forgot //&lt;/P&gt;

&lt;P&gt;[default]&lt;/P&gt;

&lt;P&gt;[WinEventLog://Application]&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
current_only = 1&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
index = tu_windows&lt;/P&gt;

&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
current_only = 1&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
blacklist = 5156|4656|33205|5158&lt;BR /&gt;
index = tu_windows&lt;/P&gt;

&lt;P&gt;[WinEventLog://System]&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
current_only = 1&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
index = tu_windows&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:36:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-Windows-events-logs-no-longer-being-forwarded-after/m-p/173504#M34896</guid>
      <dc:creator>ebailey</dc:creator>
      <dc:date>2020-09-28T18:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why are Windows events logs no longer being forwarded after universal-forwarder upgrade to 6.1.2 for Windows 2008 R2</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-Windows-events-logs-no-longer-being-forwarded-after/m-p/595842#M104059</link>
      <description>&lt;P&gt;I had a similar issue however the solution was different because I had the correct syntax (I had the forward slashes).&amp;nbsp;&lt;/P&gt;&lt;P&gt;I took the Windows TA and decided that for the WinNetMon stanza I only wanted it to go to specific windows servers as opposed to all of them in my environment. And instead of deleting the stanzas from the Splunk_TA_Windows/local/inputs.conf , I set disabled = 1. So when I created another app specific for the WinNetMon stanza and set that disabled = 0. The disabled = 1 took precedence over my custom app, hence Splunk could not find a WinNetMon stanza.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Deleting the WinNetMon stanzas from Splunk_TA_Windows/local/inputs.conf fixed my issue.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 18:27:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-Windows-events-logs-no-longer-being-forwarded-after/m-p/595842#M104059</guid>
      <dc:creator>jacbob</dc:creator>
      <dc:date>2022-04-28T18:27:34Z</dc:date>
    </item>
  </channel>
</rss>

