<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to troubleshoot why I'm receiving incomplete Windows event logs after a reboot? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-m-receiving-incomplete-Windows-event/m-p/268769#M51585</link>
    <description>&lt;P&gt;I somehow feel this is not a problem with logs not coming through, but has something to do with logs breaking at the wrong place. In your logs, look for the word "breaking". It's possible that the logs get broken at this place and it would probably be the next event or unable to find a timestamp, it is giving it a default timestamp and you would just have to do a little bit of finding.&lt;/P&gt;</description>
    <pubDate>Fri, 05 Feb 2016 00:03:57 GMT</pubDate>
    <dc:creator>abhijitmishra87</dc:creator>
    <dc:date>2016-02-05T00:03:57Z</dc:date>
    <item>
      <title>How to troubleshoot why I'm receiving incomplete Windows event logs after a reboot?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-m-receiving-incomplete-Windows-event/m-p/268768#M51584</link>
      <description>&lt;P&gt;i have configured a forwarder to send Windows event logs events to Splunk. It was working fine and sending events fully. Recently after a reboot, it has been sending only partial information. One particular field in event log events are not being sent. Can someone help to troubleshoot this?&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Events before:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;LogName=System&lt;BR /&gt;
SourceName=PRIVMAN&lt;BR /&gt;
EventCode=28695&lt;BR /&gt;
EventType=4&lt;BR /&gt;
Type=Information&lt;BR /&gt;
ComputerName=DB068038.dmn1.fmr.com&lt;BR /&gt;
User=a555345&lt;BR /&gt;
Sid=S-1-5-21-1343024091-606747145-1801674531-1316052&lt;BR /&gt;
SidType=1&lt;BR /&gt;
TaskCategory=None&lt;BR /&gt;
OpCode=None&lt;BR /&gt;
RecordNumber=111027&lt;BR /&gt;
Keywords=Classic&lt;BR /&gt;
&lt;STRONG&gt;Message=PowerBroker for Windows modified the privileges of an ActiveX control installation.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Rule Type: ActiveX&lt;BR /&gt;
Source URL: &lt;A href="http://mw100hcam3.fmr.com"&gt;http://mw100hcam3.fmr.com&lt;/A&gt;&lt;BR /&gt;
Control: dginslt.cab&lt;BR /&gt;
CLSID/MIME: {fd023c9b-082c-43f3-ada0-604fd5a1694e}&lt;BR /&gt;
Version: 2,4,0,1180&lt;BR /&gt;
Process Type: Standard User&lt;BR /&gt;
GPO Name: gpoWindows7DARE&lt;BR /&gt;
GPO GUID: {3287D455-A4DA-451A-9BBE-026CBDB8E2BA}&lt;BR /&gt;
Rule Name: ActiveX - &lt;A href="https://*.fmr.com" target="test_blank"&gt;https://*.fmr.com&lt;/A&gt;&lt;BR /&gt;
Rule GUID: 6031d9cf-e301-496b-aab1-360b645a8e30&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Events now:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;LogName=System&lt;BR /&gt;
SourceName=PRIVMAN&lt;BR /&gt;
EventCode=28695&lt;BR /&gt;
EventType=4&lt;BR /&gt;
ComputerName=DB068038.dmn1.fmr.com&lt;BR /&gt;
User=NOT_TRANSLATED&lt;BR /&gt;
Sid=S-1-5-21-1343024091-606747145-1801674531-1316052&lt;BR /&gt;
SidType=0&lt;BR /&gt;
TaskCategory=None&lt;BR /&gt;
OpCode=None&lt;BR /&gt;
RecordNumber=111029&lt;BR /&gt;
Keywords=None&lt;BR /&gt;
&lt;STRONG&gt;Message=&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Splunk is not sending the information after &lt;STRONG&gt;Message=&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2016 07:44:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-m-receiving-incomplete-Windows-event/m-p/268768#M51584</guid>
      <dc:creator>gnanaraja</dc:creator>
      <dc:date>2016-02-04T07:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I'm receiving incomplete Windows event logs after a reboot?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-m-receiving-incomplete-Windows-event/m-p/268769#M51585</link>
      <description>&lt;P&gt;I somehow feel this is not a problem with logs not coming through, but has something to do with logs breaking at the wrong place. In your logs, look for the word "breaking". It's possible that the logs get broken at this place and it would probably be the next event or unable to find a timestamp, it is giving it a default timestamp and you would just have to do a little bit of finding.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2016 00:03:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-m-receiving-incomplete-Windows-event/m-p/268769#M51585</guid>
      <dc:creator>abhijitmishra87</dc:creator>
      <dc:date>2016-02-05T00:03:57Z</dc:date>
    </item>
  </channel>
</rss>

