<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After upgrading our Windows Splunk forwarder from Splunk 6.1.2 to 6.3.1, why are application and system logs not being sent? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265583#M50944</link>
    <description>&lt;P&gt;Linux works seamlessly - have 6.3 running on all OEL boxes no problem .  Out of interest are you running the Indexer on Windows or Linux ?&lt;/P&gt;</description>
    <pubDate>Fri, 11 Dec 2015 14:14:11 GMT</pubDate>
    <dc:creator>jhingley</dc:creator>
    <dc:date>2015-12-11T14:14:11Z</dc:date>
    <item>
      <title>After upgrading our Windows Splunk forwarder from Splunk 6.1.2 to 6.3.1, why are application and system logs not being sent?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265574#M50935</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;I upgraded to a 6.3.1 Splunk forwarder on a Windows 2012 server. Connectivity is fine and Security logs are coming through, but I can't see Application or System logs (I ensured all three boxes had been checked during the installation process) - I checked 'system&amp;gt;local&amp;gt;inputs.conf' and added the stanzas detailed on this site &lt;CODE&gt;[WinEventLog://Application]&lt;/CODE&gt;, etc, but no joy .&lt;/P&gt;

&lt;P&gt;The previous version was 6.1.2 and all logs were coming through. I uninstalled the new version and put this back on - all logs were seen (I didn't need to change the inputs.conf file either) .&lt;/P&gt;

&lt;P&gt;Have checked splunkd.log after restarting the service, but I can't see a message that details what I am doing wrong - all help appreciated!&lt;/P&gt;

&lt;P&gt;btw, the Splunk Indexer and the web server are running OEL6, if this has any bearing. They are working correctly .&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2015 14:06:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265574#M50935</guid>
      <dc:creator>jhingley</dc:creator>
      <dc:date>2015-12-07T14:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading our Windows Splunk forwarder from Splunk 6.1.2 to 6.3.1, why are application and system logs not being sent?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265575#M50936</link>
      <description>&lt;P&gt;I'm having the same exact problem, except worse.&lt;BR /&gt;
This is a brand new install and only the Windows Setup event logs are being forwarded.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2015 22:19:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265575#M50936</guid>
      <dc:creator>jagould</dc:creator>
      <dc:date>2015-12-07T22:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading our Windows Splunk forwarder from Splunk 6.1.2 to 6.3.1, why are application and system logs not being sent?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265576#M50937</link>
      <description>&lt;P&gt;Glad its not just me! I am running W2K12 R1 - do you have the same setup ?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 09:13:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265576#M50937</guid>
      <dc:creator>jhingley</dc:creator>
      <dc:date>2015-12-08T09:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading our Windows Splunk forwarder from Splunk 6.1.2 to 6.3.1, why are application and system logs not being sent?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265577#M50938</link>
      <description>&lt;P&gt;i'm running 2k8R2&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 13:27:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265577#M50938</guid>
      <dc:creator>jagould</dc:creator>
      <dc:date>2015-12-08T13:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading our Windows Splunk forwarder from Splunk 6.1.2 to 6.3.1, why are application and system logs not being sent?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265578#M50939</link>
      <description>&lt;P&gt;Ok - I have just installed the forwarder on our Domain Controller (W2K12 r1) , it sends 'system' and 'application' but not 'security ' - even though I selected the same settings as the previous server . There is plenty of space on the indexer , and again I cant find a specific error message within 'splunkd.log' to pinpoint why certain event logs are not being sent .&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 13:31:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265578#M50939</guid>
      <dc:creator>jhingley</dc:creator>
      <dc:date>2015-12-08T13:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading our Windows Splunk forwarder from Splunk 6.1.2 to 6.3.1, why are application and system logs not being sent?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265579#M50940</link>
      <description>&lt;P&gt;So i have come to realise that splunk is horrible software.&lt;BR /&gt;
The only way i can get it to work, is if i setup the Forwarders to be Deployment Clients, and then "Add data" from a Forwarder and select the client that's a deployment client.&lt;BR /&gt;
Problem is, Once i a create a server class, the only way i can add to it is using the deployment*.conf on the server, which defeats the entire purpose of splunk IMO.&lt;BR /&gt;
I want everything to be fully automated (i've got scripted install of the Forwarder via WSUS using LocalUpdatePublisher) and when installed i just want the data to be send to the Indexer.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 13:07:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265579#M50940</guid>
      <dc:creator>jagould</dc:creator>
      <dc:date>2015-12-11T13:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading our Windows Splunk forwarder from Splunk 6.1.2 to 6.3.1, why are application and system logs not being sent?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265580#M50941</link>
      <description>&lt;P&gt;So i have come to realise that splunk is horrible software.&lt;BR /&gt;
The only way i can get it to work, is if i setup the Forwarders to be Deployment Clients, and then "Add data" from a Forwarder and select the client that's a deployment client.&lt;BR /&gt;
Problem is, Once i a create a server class, the only way i can add to it is using the deployment*.conf on the server, which defeats the entire purpose of splunk IMO.&lt;BR /&gt;
I want everything to be fully automated (i've got scripted install of the Forwarder via WSUS using LocalUpdatePublisher) and when installed i just want the data to be send to the Indexer.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 13:07:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265580#M50941</guid>
      <dc:creator>jagould</dc:creator>
      <dc:date>2015-12-11T13:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading our Windows Splunk forwarder from Splunk 6.1.2 to 6.3.1, why are application and system logs not being sent?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265581#M50942</link>
      <description>&lt;P&gt;I have rolled back to 6.1.8 . Its working correctly with all three logs coming through  . Trouble is we need the 'fixed' feature of data integrity (hashing of logs) for compliance that is in 6.3 .&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 13:15:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265581#M50942</guid>
      <dc:creator>jhingley</dc:creator>
      <dc:date>2015-12-11T13:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading our Windows Splunk forwarder from Splunk 6.1.2 to 6.3.1, why are application and system logs not being sent?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265582#M50943</link>
      <description>&lt;P&gt;I know what you mean.&lt;BR /&gt;
I tried 6.2.7 and it doesn't work there either for me.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 13:39:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265582#M50943</guid>
      <dc:creator>jagould</dc:creator>
      <dc:date>2015-12-11T13:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading our Windows Splunk forwarder from Splunk 6.1.2 to 6.3.1, why are application and system logs not being sent?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265583#M50944</link>
      <description>&lt;P&gt;Linux works seamlessly - have 6.3 running on all OEL boxes no problem .  Out of interest are you running the Indexer on Windows or Linux ?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 14:14:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265583#M50944</guid>
      <dc:creator>jhingley</dc:creator>
      <dc:date>2015-12-11T14:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading our Windows Splunk forwarder from Splunk 6.1.2 to 6.3.1, why are application and system logs not being sent?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265584#M50945</link>
      <description>&lt;P&gt;its running on windows. &lt;BR /&gt;
I think i just realized my issue, and i'm slightly embarrassed because it seems to simple.&lt;BR /&gt;
I'm running Splunk Light for my indexer on windows, when you enable the addon for Windows (which you need to index windows logs) it creates a Separate wineventlog index.  Apparently the ONLY way to get the Search to show this index is to manually specify it in the search "index=* host=xx" and then i can see all my source types. &lt;/P&gt;

&lt;P&gt;It's probably been working the entire time.  Now i need to find out how to include that index by default.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 14:19:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265584#M50945</guid>
      <dc:creator>jagould</dc:creator>
      <dc:date>2015-12-11T14:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading our Windows Splunk forwarder from Splunk 6.1.2 to 6.3.1, why are application and system logs not being sent?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265585#M50946</link>
      <description>&lt;P&gt;I tried 'index=_internal host=xxxxxx' but can only see 'metrics.log' and 'splunkd.log' in the source . &lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 14:39:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265585#M50946</guid>
      <dc:creator>jhingley</dc:creator>
      <dc:date>2015-12-11T14:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading our Windows Splunk forwarder from Splunk 6.1.2 to 6.3.1, why are application and system logs not being sent?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265586#M50947</link>
      <description>&lt;P&gt;OK, I'm running Splunk Light on windows, using the Universal Forwarders, NOT using Deployment server setting, but the Index Forwarder setting.&lt;BR /&gt;
So my problem was the fact that the Splunk Light be Default, only searches the Main and OS Indexes. Me being New to Splunk, this was very frustrating as i didn't know that.&lt;BR /&gt;
Once you enable the Windows Addon (which you need) it creates a wineventlog index.  All of the data from windows goes into those indexes (Application, System, Security only).&lt;BR /&gt;
The only way to get this data to show, would be to search using "index=* host=bla" to see the data i was expecting to see.&lt;/P&gt;

&lt;P&gt;I created a "authorize.conf" under Splunk/etc/system/local/  and added this to the file:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;[role_admin]&lt;BR /&gt;
srchIndexesDefault = *&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;restarted Splunk Light.&lt;/P&gt;

&lt;P&gt;Now everything shows up by default, and all my hosts show up with the correct information.&lt;/P&gt;

&lt;P&gt;Not sure if this is your issue, but i wanted to share mine since they were "similar"&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 14:55:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265586#M50947</guid>
      <dc:creator>jagould</dc:creator>
      <dc:date>2015-12-11T14:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading our Windows Splunk forwarder from Splunk 6.1.2 to 6.3.1, why are application and system logs not being sent?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265587#M50948</link>
      <description>&lt;P&gt;OK, I'm running Splunk Light on windows, using the Universal Forwarders, NOT using Deployment server setting, but the Index Forwarder setting.&lt;BR /&gt;
So my problem was the fact that the Splunk Light be Default, only searches the Main and OS Indexes. Me being New to Splunk, this was very frustrating as i didn't know that.&lt;BR /&gt;
Once you enable the Windows Addon (which you need) it creates a wineventlog index.  All of the data from windows goes into those indexes (Application, System, Security only).&lt;BR /&gt;
The only way to get this data to show, would be to search using "index=* host=bla" to see the data i was expecting to see.&lt;/P&gt;

&lt;P&gt;I created a "authorize.conf" under Splunk/etc/system/local/  and added this to the file:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;[role_admin]&lt;BR /&gt;
srchIndexesDefault = *&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;restarted Splunk Light.&lt;/P&gt;

&lt;P&gt;Now everything shows up by default, and all my hosts show up with the correct information.&lt;/P&gt;

&lt;P&gt;Not sure if this is your issue, but i wanted to share mine since they were "similar"&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 14:57:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265587#M50948</guid>
      <dc:creator>jagould</dc:creator>
      <dc:date>2015-12-11T14:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading our Windows Splunk forwarder from Splunk 6.1.2 to 6.3.1, why are application and system logs not being sent?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265588#M50949</link>
      <description>&lt;P&gt;Many thanks for that - will give it a go and report back .&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 15:10:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-our-Windows-Splunk-forwarder-from-Splunk-6-1-2/m-p/265588#M50949</guid>
      <dc:creator>jhingley</dc:creator>
      <dc:date>2015-12-11T15:10:29Z</dc:date>
    </item>
  </channel>
</rss>

