<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problems with WinEvent collection on Windows2000 Server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Problems-with-WinEvent-collection-on-Windows2000-Server/m-p/453923#M78600</link>
    <description>&lt;P&gt;Hi everybody,&lt;/P&gt;

&lt;P&gt;my client uses a UF to forward Data from a Windows 2000 server. They try to collect Winevents.&lt;/P&gt;

&lt;P&gt;Application&lt;BR /&gt;
System&lt;BR /&gt;
Security&lt;/P&gt;

&lt;P&gt;The collection itself seems to work, but we only see Application logs in Splunk. For both other event logs we get:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;WinEventLogChannel - init: Failed to bind to DC, dc_bind_time=9047 msec
WinEventLogChannel - Initialized Windows Event Log='Security' Success; oldest_rec_id='0'; newest_rec_id='0'; total_rec='0'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Which actually means that Splunk can not find any logs, but why?&lt;/P&gt;</description>
    <pubDate>Mon, 13 May 2019 14:57:46 GMT</pubDate>
    <dc:creator>jbrocks</dc:creator>
    <dc:date>2019-05-13T14:57:46Z</dc:date>
    <item>
      <title>Problems with WinEvent collection on Windows2000 Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Problems-with-WinEvent-collection-on-Windows2000-Server/m-p/453923#M78600</link>
      <description>&lt;P&gt;Hi everybody,&lt;/P&gt;

&lt;P&gt;my client uses a UF to forward Data from a Windows 2000 server. They try to collect Winevents.&lt;/P&gt;

&lt;P&gt;Application&lt;BR /&gt;
System&lt;BR /&gt;
Security&lt;/P&gt;

&lt;P&gt;The collection itself seems to work, but we only see Application logs in Splunk. For both other event logs we get:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;WinEventLogChannel - init: Failed to bind to DC, dc_bind_time=9047 msec
WinEventLogChannel - Initialized Windows Event Log='Security' Success; oldest_rec_id='0'; newest_rec_id='0'; total_rec='0'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Which actually means that Splunk can not find any logs, but why?&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 14:57:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Problems-with-WinEvent-collection-on-Windows2000-Server/m-p/453923#M78600</guid>
      <dc:creator>jbrocks</dc:creator>
      <dc:date>2019-05-13T14:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with WinEvent collection on Windows2000 Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Problems-with-WinEvent-collection-on-Windows2000-Server/m-p/453924#M78601</link>
      <description>&lt;P&gt;imho its not supported&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 00:19:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Problems-with-WinEvent-collection-on-Windows2000-Server/m-p/453924#M78601</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-05-14T00:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with WinEvent collection on Windows2000 Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Problems-with-WinEvent-collection-on-Windows2000-Server/m-p/453925#M78602</link>
      <description>&lt;P&gt;Thanks for you comment. I read similar, but I also read that Forwarding at least should work. As I said, we are just receiving Application Logs from that host - this works fine. But only no Security or System logs. (inputs.conf is fine)&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 05:47:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Problems-with-WinEvent-collection-on-Windows2000-Server/m-p/453925#M78602</guid>
      <dc:creator>jbrocks</dc:creator>
      <dc:date>2019-05-14T05:47:15Z</dc:date>
    </item>
  </channel>
</rss>

