<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why Windows Event Logs show &amp;quot;Splunk could not get the description for this event. Either ...&amp;quot; in message field in Splunk 6.1.2? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-Windows-Event-Logs-show-quot-Splunk-could-not-get-the/m-p/196524#M39102</link>
    <description>&lt;P&gt;Does this error message actually indicate anything BAD on the host or the server? I'm seeing thousands of occurrences of this issue in my environment but I still get my logs and don't seem to have any issues.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Jun 2016 15:50:33 GMT</pubDate>
    <dc:creator>patterc</dc:creator>
    <dc:date>2016-06-01T15:50:33Z</dc:date>
    <item>
      <title>Why Windows Event Logs show "Splunk could not get the description for this event. Either ..." in message field in Splunk 6.1.2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-Windows-Event-Logs-show-quot-Splunk-could-not-get-the/m-p/196520#M39098</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'm using splunk universal forwarder version 6.1.2 on Windows Servers to index EventLogs. The Events are indexed (indexer version 6.1.2), however the message field contains following message:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Splunk could not get the description for this event. Either the component that raises this event is not installed on your local computer or the installation is corrupt.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;In the Event Viewer on the Windows Server the message field is displayed correctly. I couldn't identify a specific EventID nor Server version, it happens on win server 2003 and also 2008r2. However it seems to happen mostly in Security and Application Log.&lt;/P&gt;

&lt;P&gt;If found an article that describes the problem, however it addressed a bug in 4.3.x&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/66436/splunk-could-not-get-the-description-for-this-event-4-3-2-universal-forwarder-server-2008-r2.html"&gt;http://answers.splunk.com/answers/66436/splunk-could-not-get-the-description-for-this-event-4-3-2-universal-forwarder-server-2008-r2.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Any ideas or suggestions? Could it be the same bug? &lt;/P&gt;

&lt;P&gt;thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2015 07:12:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-Windows-Event-Logs-show-quot-Splunk-could-not-get-the/m-p/196520#M39098</guid>
      <dc:creator>harald_leitl</dc:creator>
      <dc:date>2015-01-21T07:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why Windows Event Logs show "Splunk could not get the description for this event. Either ..." in message field in Splunk 6.1.2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-Windows-Event-Logs-show-quot-Splunk-could-not-get-the/m-p/196521#M39099</link>
      <description>&lt;P&gt;Same issue &lt;BR /&gt;
OS:  Windows Server 2012&lt;BR /&gt;
Universal forwarder 6.1.2.2213098&lt;BR /&gt;
Source:  WinEventLog:Security and WinEventLog:Application&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2015 15:55:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-Windows-Event-Logs-show-quot-Splunk-could-not-get-the/m-p/196521#M39099</guid>
      <dc:creator>cyndiback</dc:creator>
      <dc:date>2015-02-19T15:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why Windows Event Logs show "Splunk could not get the description for this event. Either ..." in message field in Splunk 6.1.2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-Windows-Event-Logs-show-quot-Splunk-could-not-get-the/m-p/196522#M39100</link>
      <description>&lt;P&gt;Your best bet is to follow the instructions here: &lt;A href="https://answers.splunk.com/answers/200924/formatmessage-error-appears-in-indexed-message-for.html"&gt;https://answers.splunk.com/answers/200924/formatmessage-error-appears-in-indexed-message-for.html&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2016 15:02:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-Windows-Event-Logs-show-quot-Splunk-could-not-get-the/m-p/196522#M39100</guid>
      <dc:creator>aivarson_splunk</dc:creator>
      <dc:date>2016-01-26T15:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why Windows Event Logs show "Splunk could not get the description for this event. Either ..." in message field in Splunk 6.1.2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-Windows-Event-Logs-show-quot-Splunk-could-not-get-the/m-p/196523#M39101</link>
      <description>&lt;P&gt;I am using UF 6.2.3 and I started to see this error message as well. &lt;/P&gt;

&lt;P&gt;For me, it started when I added two strings to the  inputs.conf stanza on our  Windows Domain Controllers (2008 R2).&lt;/P&gt;

&lt;P&gt;I deployed a new configs  that added the following lines to the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; file located on the forwarder at:&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\local\inputs.conf&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;I added the evt dns and dc names.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog://Security]
disabled = 0  
start_from = oldest
current_only = 0
%|250214524_4|%
...
evt_dc_name  = &amp;lt;domain name&amp;gt;
evt_dns_name =&amp;lt;domain name
... 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I was trying to see if it would help on SID EVENT translations, but really just caused the event messages to report the description error.&lt;/P&gt;

&lt;P&gt;Once I remove the lines from the stanza and restarted the splunk service, I started to received the correctly formatted events.&lt;/P&gt;

&lt;P&gt;I also seen some users install an updated version afer 6.2.x of the UF install over there current one with success. I suspect the new install just overwrote the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and now they now longer see the issue, but i am not certain.&lt;/P&gt;

&lt;P&gt;/Michael&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2016 18:02:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-Windows-Event-Logs-show-quot-Splunk-could-not-get-the/m-p/196523#M39101</guid>
      <dc:creator>michaelstillmun</dc:creator>
      <dc:date>2016-04-27T18:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why Windows Event Logs show "Splunk could not get the description for this event. Either ..." in message field in Splunk 6.1.2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-Windows-Event-Logs-show-quot-Splunk-could-not-get-the/m-p/196524#M39102</link>
      <description>&lt;P&gt;Does this error message actually indicate anything BAD on the host or the server? I'm seeing thousands of occurrences of this issue in my environment but I still get my logs and don't seem to have any issues.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2016 15:50:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-Windows-Event-Logs-show-quot-Splunk-could-not-get-the/m-p/196524#M39102</guid>
      <dc:creator>patterc</dc:creator>
      <dc:date>2016-06-01T15:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why Windows Event Logs show "Splunk could not get the description for this event. Either ..." in message f</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-Windows-Event-Logs-show-quot-Splunk-could-not-get-the/m-p/711869#M117561</link>
      <description>&lt;P&gt;Try&amp;nbsp;&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Knowledge-Management/Solutions-quot-Splunk-could-not-get-the-description-for-this/td-p/694752" target="_blank"&gt;https://community.splunk.com/t5/Knowledge-Management/Solutions-quot-Splunk-could-not-get-the-description-for-this/td-p/694752&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 15:08:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-Windows-Event-Logs-show-quot-Splunk-could-not-get-the/m-p/711869#M117561</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2025-02-17T15:08:18Z</dc:date>
    </item>
  </channel>
</rss>

