<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46451#M8756</link>
    <description>&lt;P&gt;Look at your windows event logs locally and I will bet you are getting the same message. If it is your security log you are probably missing the msaudite.dll file under system32 folder along with security subkey under the hklmsystemcurrentcontrolsetserviceseventlogsecurity. &lt;BR /&gt;
If it is in the app or system event log you are missing the registry hives for those events. You can just copy them over from a working machine.&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jul 2012 19:28:52 GMT</pubDate>
    <dc:creator>mship</dc:creator>
    <dc:date>2012-07-10T19:28:52Z</dc:date>
    <item>
      <title>WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46431#M8736</link>
      <description>&lt;P&gt;We have Universal Forwarders installed on Windows 2003 &amp;amp; 2008 Servers, plus a heavy forwarder on Windows 2008... &lt;/P&gt;

&lt;P&gt;We updated to 4.3.2 on all forwarders in April, and converted all but one system configured as heavy forwarders to universal forwarders. Most of the systems were previously running 4.2.4 heavy forwarders, though a few were running 4.3.1 Universal Forwarders.&lt;/P&gt;

&lt;P&gt;Last week I noticed, 11 of my 15 Windows forwarders displayed the "Splunk could not get the description for this event" message in 4,647 events for a 24 hour period, excluding domain controller security logs (in which case it goes into the millions). In the case of the domain controller, cycling the SplunkForwarder service once or twice usually clears up the messages from the WinEventLog:Security, though I'll continue to get the error message on the DCs in the Application and System Logs.&lt;/P&gt;

&lt;BLOCKQUOTE&gt;&lt;CODE&gt;05/08/2012 01:19:29 PM
LogName=System
SourceName=Service Control Manager
EventCode=7040
EventType=4
ComputerName=DC2.hersheymed.net
User=SYSTEM
Sid=S-1-5-18
SidType=1
TaskCategory=None
OpCode=None
RecordNumber=211980
Keywords=None
Message=Splunk could not get the description for this event. Either the component that raises this event is not installed on your local computer or the installation is corrupt.

FormatMessage error: The handle is invalid.

Got the following information from this event: 

Windows Modules Installer
demand start
auto start
TrustedInstaller&lt;/CODE&gt;&lt;/BLOCKQUOTE&gt;

&lt;P&gt;All 11 are Windows 2008(32-bit, 64-bit, and R2), the other four are all Windows 2003. The number of messages in the System and Application logs that display this behavior far exceeds the number of messages that do not. Indexes are 4.3.2 on RedHat, in case it matters. There are no (or very few if they're buried in the data) events with this behavior prior to updating the forwarder on any given host.&lt;/P&gt;

&lt;P&gt;I've had a support case open since late last week, but I thought I'd ask the community if they can think of anything to check while I'm waiting... we're continuing to pull in corrupt (well, incomplete anyway) log data from these Windows forwarders so the delay in the back-and-forth-by-email isn't appealing.&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2012 17:27:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46431#M8736</guid>
      <dc:creator>jeff</dc:creator>
      <dc:date>2012-05-08T17:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46432#M8737</link>
      <description>&lt;P&gt;Can you enable splunk logging? In etc\log.cfg set the following flags to DEBUG&lt;BR /&gt;
category.WinEventLogAgent=DEBUG &lt;BR /&gt;&lt;BR /&gt;
category.WinEventLogInputProcessor=DEBUG &lt;BR /&gt;&lt;BR /&gt;
category.WinEventLogChannel=DEBUG &lt;BR /&gt;&lt;BR /&gt;
category.WinEventLog=DEBUG &lt;BR /&gt;&lt;/P&gt;

&lt;P&gt;restart splunk and look into var\splunkd.log for possible errors&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2012 19:58:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46432#M8737</guid>
      <dc:creator>rovechkin_splun</dc:creator>
      <dc:date>2012-05-08T19:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46433#M8738</link>
      <description>&lt;P&gt;Yeah, I had done that for support... generates a lot of messages like the following:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;&lt;CODE&gt;DEBUG WinEventLogChannel - formatMessageByFlag: EvtFormatMessage returned no message, flag='(7)EvtFormatMessageProvider', channel='System', 'The handle is invalid.'

WinEventLogChannel - getEventsNew: Failed to format source name of event log, channel='System', rec_id=434438 'The handle is invalid.'
&lt;/CODE&gt;&lt;/BLOCKQUOTE&gt;

&lt;P&gt;several times for each event it couldn't process, but other than that not much useful. I downgraded to 4.3.1 on one forwarder yesterday and so far no errors...&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2012 13:48:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46433#M8738</guid>
      <dc:creator>jeff</dc:creator>
      <dc:date>2012-05-09T13:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46434#M8739</link>
      <description>&lt;P&gt;I'm also getting a lot of these messages since upgrading my Windows Universal Forwarders to 4.3.2. I have a number of Universal Forwarders running on Windows 2008 R2 all forwarding to a single 4.3.2 indexer running on Linux.&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2012 09:30:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46434#M8739</guid>
      <dc:creator>marksnelling</dc:creator>
      <dc:date>2012-05-10T09:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46435#M8740</link>
      <description>&lt;P&gt;Our site has also encountered this.  Smells like a bug as it has only occurred with the 4.3.2 UF, not with the previous version of UF (4.2.x)&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2012 21:30:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46435#M8740</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2012-05-11T21:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46436#M8741</link>
      <description>&lt;P&gt;Have you considered downgrading the forwarder?  We're not seeing this issue with UF 4.2.5.&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2012 21:31:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46436#M8741</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2012-05-11T21:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46437#M8742</link>
      <description>&lt;P&gt;yeah, support is finally filing a bug report...&lt;/P&gt;</description>
      <pubDate>Sun, 13 May 2012 01:26:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46437#M8742</guid>
      <dc:creator>jeff</dc:creator>
      <dc:date>2012-05-13T01:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46438#M8743</link>
      <description>&lt;P&gt;The likely relevant change was from 4.3.1 to 4.3.2; I would recommend using 4.3.1 for now.  An example specific message which behaved that way would be useful.&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2012 00:50:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46438#M8743</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2012-05-14T00:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46439#M8744</link>
      <description>&lt;P&gt;You mean, other than the sample message in the post?... if you read through the rest of the post you'll see that I downgraded to 4.3.1 on key forwarders and the symptoms went away. Support is entering a bug report for me, as of late Friday afternoon.&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2012 12:52:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46439#M8744</guid>
      <dc:creator>jeff</dc:creator>
      <dc:date>2012-05-14T12:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46440#M8745</link>
      <description>&lt;P&gt;I meant the message as it should have been gathered; for example as it appears with 4.3.1 or in event log viewer.  I'm working on the bug -- and more information will help.&lt;BR /&gt;
; well the problem turned out to have not much relationship with the message, so nevermind.&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2012 22:06:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46440#M8745</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2012-05-14T22:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46441#M8746</link>
      <description>&lt;P&gt;Hm, I answered this, but the comment system ate it whole.  Trying again.&lt;/P&gt;

&lt;P&gt;This is indeed a bug in 4.3.2 WinEventLog data acquisition code.  It's now been identified and we can fix for the next release.&lt;/P&gt;

&lt;P&gt;The code flow was altered in order to address performance concerns, which was a success.  The performance for rapidly acquiring eventlog data should improve by around a factor of 2, which relieves stress on the wineventlog service (which was the bottleneck).  The changes have to do with cacheing handles for data providers of windows eventlog strings.&lt;/P&gt;

&lt;P&gt;Of course that's a poor consolation for correct operation.  Unfortunately, the set of events we tested with did not have the distribution of data providers, so the problem wasn't identified internally.  &lt;/P&gt;

&lt;P&gt;For now please use 4.3.1 forwarders (or earlier) to acquire this data type.  &lt;/P&gt;

&lt;P&gt;Please note that this error message does not have a one to one correlation with this misbehavior.  Other scenarios such as loading EVT files without the corresponding availble DLLs that provide the messages, or reading eventlogs for an application which has been subsequently uninstalled could (and do) produce the same message.&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2012 05:51:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46441#M8746</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2012-05-16T05:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46442#M8747</link>
      <description>&lt;P&gt;Where can I download 4.3.1?&lt;/P&gt;</description>
      <pubDate>Sat, 19 May 2012 01:59:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46442#M8747</guid>
      <dc:creator>coreindustries</dc:creator>
      <dc:date>2012-05-19T01:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46443#M8748</link>
      <description>&lt;P&gt;@coreindustries - &lt;A href="http://www.splunk.com/page/previous_releases"&gt;http://www.splunk.com/page/previous_releases&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2012 13:29:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46443#M8748</guid>
      <dc:creator>farren</dc:creator>
      <dc:date>2012-05-21T13:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46444#M8749</link>
      <description>&lt;P&gt;Where can i get Universal forwarder 4.3.1 ??&lt;BR /&gt;
Done!! Thank you!!! (Older versions link in the same download web ....)&lt;/P&gt;

&lt;P&gt;Instead of the forwarder 4.3.1 the message of the event is not showed. Same message 'Splunk could not get ...'&lt;/P&gt;

&lt;P&gt;Any idea?&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2012 15:38:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46444#M8749</guid>
      <dc:creator>gpt</dc:creator>
      <dc:date>2012-05-22T15:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46445#M8750</link>
      <description>&lt;P&gt;I had the same issue, and now I'm downgrading the universal forwarder: hope it can solve the bug &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2012 10:56:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46445#M8750</guid>
      <dc:creator>bizza</dc:creator>
      <dc:date>2012-05-24T10:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46446#M8751</link>
      <description>&lt;P&gt;Any timeline for the release of 4.3.3?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2012 13:36:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46446#M8751</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2012-06-05T13:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46447#M8752</link>
      <description>&lt;P&gt;For searching purposes, this issues is listed as SPL-51312.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2012 13:43:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46447#M8752</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2012-06-05T13:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46448#M8753</link>
      <description>&lt;P&gt;In May I was told 4.3.3 was targeted for July.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2012 14:13:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46448#M8753</guid>
      <dc:creator>jeff</dc:creator>
      <dc:date>2012-06-11T14:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46449#M8754</link>
      <description>&lt;P&gt;Rolling back to 4.3.1 UF did not work for me...any other suggestions?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2012 12:47:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46449#M8754</guid>
      <dc:creator>mship</dc:creator>
      <dc:date>2012-06-19T12:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:* on Windows 2008 and Splunk 4.3.2 forwarders - Splunk could not get the description for this event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46450#M8755</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;what the SPL number for this?&lt;/P&gt;

&lt;P&gt;Kind Regards,&lt;/P&gt;

&lt;P&gt;Jens&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2012 16:08:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-on-Windows-2008-and-Splunk-4-3-2-forwarders-Splunk/m-p/46450#M8755</guid>
      <dc:creator>JensT</dc:creator>
      <dc:date>2012-06-20T16:08:00Z</dc:date>
    </item>
  </channel>
</rss>

