<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WinEventMon::processLogChannel unable to checkpoint in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/WinEventMon-processLogChannel-unable-to-checkpoint/m-p/112574#M97601</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;
I have all my Splunk Universal Forwarders on Windows 2008 R2 machines that are generating this error:&lt;/P&gt;

&lt;P&gt;ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - WinEventMon::processLogChannel: Failed to checkpoint for channel='security'&lt;/P&gt;

&lt;P&gt;The only modification that I have made is to the inputs.conf file adding:&lt;/P&gt;

&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
whitelist = 4624,4625,4634,4656,4659,4660&lt;/P&gt;

&lt;P&gt;Any suggestion?&lt;/P&gt;

&lt;P&gt;Regards&lt;BR /&gt;
Danilo Massa&lt;/P&gt;</description>
    <pubDate>Mon, 31 Mar 2014 10:14:36 GMT</pubDate>
    <dc:creator>danilom</dc:creator>
    <dc:date>2014-03-31T10:14:36Z</dc:date>
    <item>
      <title>WinEventMon::processLogChannel unable to checkpoint</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventMon-processLogChannel-unable-to-checkpoint/m-p/112574#M97601</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I have all my Splunk Universal Forwarders on Windows 2008 R2 machines that are generating this error:&lt;/P&gt;

&lt;P&gt;ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - WinEventMon::processLogChannel: Failed to checkpoint for channel='security'&lt;/P&gt;

&lt;P&gt;The only modification that I have made is to the inputs.conf file adding:&lt;/P&gt;

&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
whitelist = 4624,4625,4634,4656,4659,4660&lt;/P&gt;

&lt;P&gt;Any suggestion?&lt;/P&gt;

&lt;P&gt;Regards&lt;BR /&gt;
Danilo Massa&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2014 10:14:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventMon-processLogChannel-unable-to-checkpoint/m-p/112574#M97601</guid>
      <dc:creator>danilom</dc:creator>
      <dc:date>2014-03-31T10:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventMon::processLogChannel unable to checkpoint</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventMon-processLogChannel-unable-to-checkpoint/m-p/112575#M97602</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;same here. &lt;/P&gt;

&lt;P&gt;I'm using the blacklist option instead.&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;

&lt;P&gt;Andreas&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2014 11:32:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventMon-processLogChannel-unable-to-checkpoint/m-p/112575#M97602</guid>
      <dc:creator>andreasz</dc:creator>
      <dc:date>2014-04-01T11:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventMon::processLogChannel unable to checkpoint</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventMon-processLogChannel-unable-to-checkpoint/m-p/112576#M97603</link>
      <description>&lt;P&gt;Sorry ... my fault I have found that changing inputs.conf on a Universal Forwarder is not an option on Splunk 6.0.2.&lt;BR /&gt;
So I have put this filter on the props/transforms on the index server.&lt;/P&gt;

&lt;P&gt;Regards&lt;BR /&gt;
Danilo&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2014 12:03:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventMon-processLogChannel-unable-to-checkpoint/m-p/112576#M97603</guid>
      <dc:creator>danilom</dc:creator>
      <dc:date>2014-04-01T12:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventMon::processLogChannel unable to checkpoint</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventMon-processLogChannel-unable-to-checkpoint/m-p/112577#M97604</link>
      <description>&lt;P&gt;"...I have found that changing inputs.conf on a Universal Forwarder is not an option on Splunk 6.0.2."&lt;/P&gt;

&lt;P&gt;Is this a known bug?&lt;BR /&gt;
According to the documentation it's still valid&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.2/admin/inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.0.2/admin/inputsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;And here is a blog from Adrian Hall&lt;/P&gt;

&lt;P&gt;&lt;A href="http://blogs.splunk.com/2013/10/14/windows-event-logs-in-splunk-6/"&gt;http://blogs.splunk.com/2013/10/14/windows-event-logs-in-splunk-6/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;"I included two techniques – firstly, filtering by event code so that you didn’t include the events you didn’t want; and secondly, filtering the explanatory text on the end of each event."&lt;BR /&gt;
"Let’s say you don’t want firewall events. From the previous blog post, event ID 5156 and 5157 detail the firewall connection accept and deny messages. Let’s say those are not relevant to us. Previously, we had to add a props.conf stanza to initiate a filtering action that was done in transforms.conf – it was complicated. In Splunk 6, everything is done in inputs.conf."&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2014 13:20:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventMon-processLogChannel-unable-to-checkpoint/m-p/112577#M97604</guid>
      <dc:creator>andreasz</dc:creator>
      <dc:date>2014-04-01T13:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventMon::processLogChannel unable to checkpoint</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventMon-processLogChannel-unable-to-checkpoint/m-p/112578#M97605</link>
      <description>&lt;P&gt;From &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.2/Forwarding/Typesofforwarders#Forwarder_comparison"&gt;http://docs.splunk.com/Documentation/Splunk/6.0.2/Forwarding/Typesofforwarders#Forwarder_comparison&lt;/A&gt; seems that filtering in not supported on Universal Forwarder ...&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 07:09:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventMon-processLogChannel-unable-to-checkpoint/m-p/112578#M97605</guid>
      <dc:creator>danilom</dc:creator>
      <dc:date>2014-04-02T07:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventMon::processLogChannel unable to checkpoint</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventMon-processLogChannel-unable-to-checkpoint/m-p/112579#M97606</link>
      <description>&lt;P&gt;"...seems that filtering in not supported on Universal Forwarder"&lt;/P&gt;

&lt;P&gt;It's only supported for Windows EventLogs as described in the input.conf documentation:&lt;BR /&gt;
Filtering in input.conf on the indexer wouldn't make any sense. You could only filter the Windows EventLogs on the indexer. It works for UF. &lt;/P&gt;

&lt;P&gt;# Windows Event Log Monitor&lt;/P&gt;

&lt;P&gt;blacklist = &amp;lt;&amp;lt; list &amp;gt;&amp;gt;&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Tells Splunk which event IDs and/or event ID ranges that incoming events must NOT have 
in order to be indexed.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Optional. This parameter can be left empty.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;A comma separated list of event ID and event ID ranges to exclude&lt;/STRONG&gt; (example: 4,5,7,100-200).&lt;/LI&gt;
&lt;LI&gt;If no value is present, then there is no effect.&lt;/LI&gt;
&lt;LI&gt;If you specify both the "whitelist" and "blacklist" attributes, the input ignores the
"blacklist" attribute.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;whitelist = &amp;lt;&amp;lt; list &amp;gt;&amp;gt;&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Tells Splunk which event IDs and/or event ID ranges that incoming events must have 
in order to be indexed.&lt;/LI&gt;
&lt;LI&gt;Optional. This parameter can be left empty.&lt;/LI&gt;
&lt;LI&gt;A comma-separated list of event ID and event ID ranges to include (example: 4,5,7,100-200).&lt;/LI&gt;
&lt;LI&gt;If no value is present, defaults to include all event IDs. &lt;/LI&gt;
&lt;LI&gt;If you specify both the "whitelist" and "blacklist" attributes, the input ignores the
"blacklist" attribute.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 02 Apr 2014 09:29:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventMon-processLogChannel-unable-to-checkpoint/m-p/112579#M97606</guid>
      <dc:creator>andreasz</dc:creator>
      <dc:date>2014-04-02T09:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventMon::processLogChannel unable to checkpoint</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventMon-processLogChannel-unable-to-checkpoint/m-p/112580#M97607</link>
      <description>&lt;P&gt;Filtering of Windows Event using  whitelist = &amp;lt;&amp;lt; list &amp;gt;&amp;gt;  or blacklist = &amp;lt;&amp;lt; list &amp;gt;&amp;gt;, does work on Universal Forwarder in 6.x. Also, in my environment using stanza like below does not cause the warning. &lt;/P&gt;

&lt;P&gt;...\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local\inputs.conf          [WinEventLog://Security]&lt;BR /&gt;
...\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local\inputs.conf          blacklist = 5156&lt;BR /&gt;
...\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\default\inputs.conf        checkpointInterval = 5&lt;BR /&gt;
...\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\default\inputs.conf        current_only = 0&lt;BR /&gt;
...\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local\inputs.conf          disabled = 0&lt;BR /&gt;
...\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\default\inputs.conf        evt_dc_name = &lt;BR /&gt;
...\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\default\inputs.conf        evt_dns_name = &lt;BR /&gt;
...\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\default\inputs.conf        evt_resolve_ad_obj = 1&lt;BR /&gt;
...\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\default\inputs.conf        start_from = oldest&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:35:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventMon-processLogChannel-unable-to-checkpoint/m-p/112580#M97607</guid>
      <dc:creator>rbal_splunk</dc:creator>
      <dc:date>2020-09-28T16:35:19Z</dc:date>
    </item>
  </channel>
</rss>

