<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal forwarder is not collecting events on Forwarded Folder of windows server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-is-not-collecting-events-on-Forwarded-Folder/m-p/49090#M9329</link>
    <description>&lt;P&gt;They fixed the docs on inputs.conf.    @rovechikin  Should of submitted a change on the docs inputs.conf page to save people the frustration.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Feb 2013 18:51:04 GMT</pubDate>
    <dc:creator>kmjackson788</dc:creator>
    <dc:date>2013-02-06T18:51:04Z</dc:date>
    <item>
      <title>Universal forwarder is not collecting events on Forwarded Folder of windows server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-is-not-collecting-events-on-Forwarded-Folder/m-p/49087#M9326</link>
      <description>&lt;P&gt;Hi All I am new to Splunk and having some issue...&lt;/P&gt;

&lt;P&gt;we have a windows 2008r2 server setup as an event collector for windows servers. Event logs from  windows server is being forwarded to this server and goes on  to "Forwarded Events" folder.&lt;/P&gt;

&lt;P&gt;Now I installed universal forwarder on this server with only "Forwarded Events Log" selected. When i go to splunk server, I can't see any events coming.&lt;/P&gt;

&lt;P&gt;if I install with other option selected(e.g. Application Log), I can see application log of that server appearing on splunk server.&lt;/P&gt;

&lt;P&gt;I was wondering if i am missing something and will appreciate if some one can guide me.&lt;/P&gt;

&lt;P&gt;Note:- we have decided not to install splunk agents in every server and not to use wmi as the number of windows we have is lot(in hundreds).&lt;/P&gt;

&lt;P&gt;Thank you in Advance. &lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2012 06:28:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-is-not-collecting-events-on-Forwarded-Folder/m-p/49087#M9326</guid>
      <dc:creator>AKG</dc:creator>
      <dc:date>2012-05-11T06:28:59Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder is not collecting events on Forwarded Folder of windows server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-is-not-collecting-events-on-Forwarded-Folder/m-p/49088#M9327</link>
      <description>&lt;P&gt;the is a slight bug in default configuration. The issue is that "Forwarded Events" have a space between them, while Windows ForwardedEvents event log doesn't. The workaround is to find all occurrences of "Forwarded Events" in *.conf stanzas and remove space, e.g. &lt;BR /&gt;&lt;BR /&gt;
Splunk\etc&amp;gt;find /s "Forwarded Events" *.conf &lt;BR /&gt;&lt;BR /&gt;
inputs.conf: [WinEventLog:Forwarded Events] &lt;BR /&gt;&lt;/P&gt;

&lt;P&gt;replace with [WinEventLog:ForwardedEvents] &lt;BR /&gt;&lt;BR /&gt;
reboot Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2012 18:20:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-is-not-collecting-events-on-Forwarded-Folder/m-p/49088#M9327</guid>
      <dc:creator>rovechkin_splun</dc:creator>
      <dc:date>2012-05-22T18:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder is not collecting events on Forwarded Folder of windows server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-is-not-collecting-events-on-Forwarded-Folder/m-p/49089#M9328</link>
      <description>&lt;P&gt;That fixes it.&lt;/P&gt;

&lt;P&gt;%SystemRoot%\System32\Winevt\Logs\ForwardedEvents.evtx&lt;/P&gt;

&lt;P&gt;The space  [WinEventLog:Forwarded Events]  does not work. Hopefully they fixed the documentation. ( I sent a documentation fix)&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.1/admin/Inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.1/admin/Inputsconf&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;I dont have enough credit to upvote the above answer.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2013 14:39:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-is-not-collecting-events-on-Forwarded-Folder/m-p/49089#M9328</guid>
      <dc:creator>kmjackson788</dc:creator>
      <dc:date>2013-02-06T14:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder is not collecting events on Forwarded Folder of windows server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-is-not-collecting-events-on-Forwarded-Folder/m-p/49090#M9329</link>
      <description>&lt;P&gt;They fixed the docs on inputs.conf.    @rovechikin  Should of submitted a change on the docs inputs.conf page to save people the frustration.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2013 18:51:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-is-not-collecting-events-on-Forwarded-Folder/m-p/49090#M9329</guid>
      <dc:creator>kmjackson788</dc:creator>
      <dc:date>2013-02-06T18:51:04Z</dc:date>
    </item>
  </channel>
</rss>

