<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ERROR WinEventLogChannel - initOld: Failed to initialize checkpoint for Windows Event Log channel 'Security'   Host is no longer forwarding WinEventLog:Security to the Linux indexer. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-WinEventLogChannel-initOld-Failed-to-initialize-checkpoint/m-p/41843#M7783</link>
    <description>&lt;P&gt;This is a known defect, SPL-31339: WinEventLog:Security logs stop getting indexed and Splunkd.log displays the following errors:&lt;/P&gt;

&lt;P&gt;ERROR WinEventLogChannel - initOld: Failed to initialize checkpoint for Windows Event Log channel 'Security'
ERROR WinEventLogInputProcessor - main-thread: Failed to initialize Windows Event Log 'Security'&lt;/P&gt;

&lt;P&gt;This is likely due the Windows host not shutting down properly and the  %SPLUNK_HOME%\var\lib\splunk\persistentstorage\WinEventLog\Security_checkpoint file is empty (size =1KB)&lt;/P&gt;

&lt;P&gt;The workaround is to shutdown Splunk on the Windows host, remove the file and restart Splunk to create a new Security_checkpoint file.  This will allow the security logs to start indexing again.&lt;/P&gt;

&lt;P&gt;This defect is fixed in 4.1.4 (see &lt;A href="http://www.splunk.com/base/Documentation/latest/ReleaseNotes/4.1.4" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/ReleaseNotes/4.1.4&lt;/A&gt;) 
For 4.0.x, the fix is not currently planned and the workaround should be implemented.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Sep 2010 03:02:02 GMT</pubDate>
    <dc:creator>Ellen</dc:creator>
    <dc:date>2010-09-02T03:02:02Z</dc:date>
    <item>
      <title>ERROR WinEventLogChannel - initOld: Failed to initialize checkpoint for Windows Event Log channel 'Security'   Host is no longer forwarding WinEventLog:Security to the Linux indexer.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-WinEventLogChannel-initOld-Failed-to-initialize-checkpoint/m-p/41842#M7782</link>
      <description>&lt;P&gt;All of a sudden my 4.0.9 Splunk server is no longer forwarding the WinEventLog:Security logs onto my 4.1.4 Linux indexer.  This was working fine and I can see the communication is established between the 2 systems.   What's at issue?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2010 03:01:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-WinEventLogChannel-initOld-Failed-to-initialize-checkpoint/m-p/41842#M7782</guid>
      <dc:creator>Ellen</dc:creator>
      <dc:date>2010-09-02T03:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR WinEventLogChannel - initOld: Failed to initialize checkpoint for Windows Event Log channel 'Security'   Host is no longer forwarding WinEventLog:Security to the Linux indexer.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-WinEventLogChannel-initOld-Failed-to-initialize-checkpoint/m-p/41843#M7783</link>
      <description>&lt;P&gt;This is a known defect, SPL-31339: WinEventLog:Security logs stop getting indexed and Splunkd.log displays the following errors:&lt;/P&gt;

&lt;P&gt;ERROR WinEventLogChannel - initOld: Failed to initialize checkpoint for Windows Event Log channel 'Security'
ERROR WinEventLogInputProcessor - main-thread: Failed to initialize Windows Event Log 'Security'&lt;/P&gt;

&lt;P&gt;This is likely due the Windows host not shutting down properly and the  %SPLUNK_HOME%\var\lib\splunk\persistentstorage\WinEventLog\Security_checkpoint file is empty (size =1KB)&lt;/P&gt;

&lt;P&gt;The workaround is to shutdown Splunk on the Windows host, remove the file and restart Splunk to create a new Security_checkpoint file.  This will allow the security logs to start indexing again.&lt;/P&gt;

&lt;P&gt;This defect is fixed in 4.1.4 (see &lt;A href="http://www.splunk.com/base/Documentation/latest/ReleaseNotes/4.1.4" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/ReleaseNotes/4.1.4&lt;/A&gt;) 
For 4.0.x, the fix is not currently planned and the workaround should be implemented.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2010 03:02:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-WinEventLogChannel-initOld-Failed-to-initialize-checkpoint/m-p/41843#M7783</guid>
      <dc:creator>Ellen</dc:creator>
      <dc:date>2010-09-02T03:02:02Z</dc:date>
    </item>
  </channel>
</rss>

