<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to troubleshoot why Windows event logs are not making into the target index? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Windows-event-logs-are-not-making-into/m-p/223078#M43698</link>
    <description>&lt;P&gt;That seems to look right.  What version of Splunk?  Do you get any events from the dc in Splunk (internal events included)?  Any other events from the event log on that dc?  Any event log events from any forwarders?  Where is your inputs.conf located?&lt;/P&gt;</description>
    <pubDate>Tue, 16 Aug 2016 01:15:12 GMT</pubDate>
    <dc:creator>maciep</dc:creator>
    <dc:date>2016-08-16T01:15:12Z</dc:date>
    <item>
      <title>How to troubleshoot why Windows event logs are not making into the target index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Windows-event-logs-are-not-making-into/m-p/223077#M43697</link>
      <description>&lt;P&gt;We are monitoring for specific Windows events on our Domain Controllers.&lt;BR /&gt;
Inputs.conf looks like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog://Security]
disabled = 0
index = winevents
start_from = oldest
current_only = 0
checkpointInterval = 5
whitelist = 4728,4729,4732,4733,4756,4757,4755
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Whe I add a test user to a universal security group, I trigger an event in the security log:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Log Name:      Security
Source:        Microsoft-Windows-Security-Auditing
Date:          8/11/2016 3:22:50 PM
Event ID:      4756
Task Category: Security Group Management
Level:         Information
Keywords:      Audit Success
User:          N/A
Computer:      xxxxxxxxxxxx
Description:
A member was added to a security-enabled universal group.

Subject:
    Security ID:        LONDON\xxxxxxxxxxxx
    Account Name:       xxxxxxx
    Account Domain:     LONDON
    Logon ID:       0x86xxxx

Member:
    Security ID:        LONDON\splunk_test
    Account Name:       CN=Splunk Test Log Generator UK,OU=xxx,OU=Test Area,OU=xxx,OU=OIAL,DC=xxx,DC=xxx,DC=xxx

Group:
    Security ID:        LONDON\xxxxxx
    Account Name:       xxxxxxxxxxxx
    Account Domain:     LONDON

Additional Information:
    Privileges:     -
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Event Xml:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" /&amp;gt;
EventID&amp;gt;**4756**

etc etc
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;But this event never makes it into the index.&lt;BR /&gt;
No errors on the splunkd log.&lt;BR /&gt;
What am i missing?&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2016 18:32:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Windows-event-logs-are-not-making-into/m-p/223077#M43697</guid>
      <dc:creator>davidjohnbecket</dc:creator>
      <dc:date>2016-08-11T18:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why Windows event logs are not making into the target index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Windows-event-logs-are-not-making-into/m-p/223078#M43698</link>
      <description>&lt;P&gt;That seems to look right.  What version of Splunk?  Do you get any events from the dc in Splunk (internal events included)?  Any other events from the event log on that dc?  Any event log events from any forwarders?  Where is your inputs.conf located?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 01:15:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Windows-event-logs-are-not-making-into/m-p/223078#M43698</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2016-08-16T01:15:12Z</dc:date>
    </item>
  </channel>
</rss>

