<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: windows application log files. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442824#M77137</link>
    <description>&lt;P&gt;So is the config above ok ( without the typo).&lt;/P&gt;

&lt;P&gt;we are setup for port 9998 using ssl certs signed by the client. And we do have other forwarders that are working ok.&lt;/P&gt;

&lt;P&gt;I can see the new indexer now found a config error.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Dec 2018 21:38:01 GMT</pubDate>
    <dc:creator>alanhowlett</dc:creator>
    <dc:date>2018-12-20T21:38:01Z</dc:date>
    <item>
      <title>windows application log files.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442820#M77133</link>
      <description>&lt;P&gt;I'm trying to configure splunk to ingest two application logfiles, not the event logs the actual application logfile (text).&lt;/P&gt;

&lt;P&gt;Its my first time ingesting windows forwarder logs (I'm a linux man really), but I did read that it can be done in the inputs.conf so I tried the below:&lt;/P&gt;

&lt;P&gt;[monitor://D:\lfbank\wincsl\logs\wincsl-service.log]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
index = wincsl&lt;BR /&gt;
souurcetype = lfab_wincsl1&lt;/P&gt;

&lt;P&gt;[monitor://D:\inetpub\logs\logfiles\W3SVC*]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
index = wincsl&lt;BR /&gt;
souurcetype = lfab_wincsl2&lt;/P&gt;

&lt;P&gt;I do have an outputs.conf configured, but am still seeing no data.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 17:04:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442820#M77133</guid>
      <dc:creator>alanhowlett</dc:creator>
      <dc:date>2018-12-20T17:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: windows application log files.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442821#M77134</link>
      <description>&lt;P&gt;Does the wincsl index exist?  Also, not sure if this is a typo in your question, or if this is the way your inputs.conf looks, but sourcetype is spelled incorrectly  It has two u's.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 17:11:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442821#M77134</guid>
      <dc:creator>kmorris_splunk</dc:creator>
      <dc:date>2018-12-20T17:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: windows application log files.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442822#M77135</link>
      <description>&lt;P&gt;Corrected the typo drrrrrr. Still not working.&lt;/P&gt;

&lt;P&gt;If I look in the GUI I don't see the index, but I have another built and that does show up either. But works.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 17:24:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442822#M77135</guid>
      <dc:creator>alanhowlett</dc:creator>
      <dc:date>2018-12-20T17:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: windows application log files.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442823#M77136</link>
      <description>&lt;P&gt;Set your search to All Time, just in case there are timestamping issues.  You can also click on the Data Summary which has host, source and sourcetype tabs where you can look at all of the values for each to see if you can see the values you are expecting for any of those metadata fields.&lt;/P&gt;

&lt;P&gt;Also, make sure you have no firewalls blocking the traffic.  I'm making the assumption that you are already listening on port 9997 on your indexers as well. &lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 21:30:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442823#M77136</guid>
      <dc:creator>kmorris_splunk</dc:creator>
      <dc:date>2018-12-20T21:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: windows application log files.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442824#M77137</link>
      <description>&lt;P&gt;So is the config above ok ( without the typo).&lt;/P&gt;

&lt;P&gt;we are setup for port 9998 using ssl certs signed by the client. And we do have other forwarders that are working ok.&lt;/P&gt;

&lt;P&gt;I can see the new indexer now found a config error.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 21:38:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442824#M77137</guid>
      <dc:creator>alanhowlett</dc:creator>
      <dc:date>2018-12-20T21:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: windows application log files.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442825#M77138</link>
      <description>&lt;P&gt;What does your splunk forwarder logs say, are there any lines including the names of these logs?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 22:35:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442825#M77138</guid>
      <dc:creator>briancronrath</dc:creator>
      <dc:date>2018-12-20T22:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: windows application log files.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442826#M77139</link>
      <description>&lt;P&gt;I don't have access to the forwarders. I'm just using the deployment server to send the configs out.&lt;/P&gt;

&lt;P&gt;I'm going to have to check things tomorrow with the engineer on site.&lt;/P&gt;

&lt;P&gt;As long as my syntax is ok.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 22:57:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442826#M77139</guid>
      <dc:creator>alanhowlett</dc:creator>
      <dc:date>2018-12-20T22:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: windows application log files.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442827#M77140</link>
      <description>&lt;P&gt;You need to add &lt;CODE&gt;WindEventLog:Application&lt;/CODE&gt; stanza before monitor.&lt;BR /&gt;
For Example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog:Application]
disabled = 0
start_from = oldest
current_only = 0
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 28 Jan 2020 23:13:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-application-log-files/m-p/442827#M77140</guid>
      <dc:creator>vsai0718</dc:creator>
      <dc:date>2020-01-28T23:13:06Z</dc:date>
    </item>
  </channel>
</rss>

