<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WinEventLog in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/510301#M8262</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223950"&gt;@Jeronimo317&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is your setup? Are you trying to forward wineventlog from remote server to splunk using universal forwarder?&lt;/P&gt;&lt;P&gt;Please make sure you have the following configurations in place&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;open port 9997 on receiving instance&lt;/LI&gt;&lt;LI&gt;configure outputs.conf on UF to send data to splunk indexer&lt;/LI&gt;&lt;LI&gt;open network connection (for port 9997) between remote server &amp;amp; splunk instance&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Please refer below page for more details&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/8.0.5/Forwarder/HowtoforwarddatatoSplunkEnterprise" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/8.0.5/Forwarder/HowtoforwarddatatoSplunkEnterprise&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jul 2020 21:28:41 GMT</pubDate>
    <dc:creator>anilchaithu</dc:creator>
    <dc:date>2020-07-21T21:28:41Z</dc:date>
    <item>
      <title>WinEventLog</title>
      <link>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/510293#M8259</link>
      <description>&lt;P&gt;Hi team, the issue that I am currently experiencing is that WinEventLog not sending data to the main index . I am new to Splunk and so far have not been able to figure out the reason. Thoughts?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2020 21:04:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/510293#M8259</guid>
      <dc:creator>Jeronimo317</dc:creator>
      <dc:date>2020-07-21T21:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog</title>
      <link>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/510301#M8262</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223950"&gt;@Jeronimo317&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is your setup? Are you trying to forward wineventlog from remote server to splunk using universal forwarder?&lt;/P&gt;&lt;P&gt;Please make sure you have the following configurations in place&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;open port 9997 on receiving instance&lt;/LI&gt;&lt;LI&gt;configure outputs.conf on UF to send data to splunk indexer&lt;/LI&gt;&lt;LI&gt;open network connection (for port 9997) between remote server &amp;amp; splunk instance&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Please refer below page for more details&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/8.0.5/Forwarder/HowtoforwarddatatoSplunkEnterprise" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/8.0.5/Forwarder/HowtoforwarddatatoSplunkEnterprise&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2020 21:28:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/510301#M8262</guid>
      <dc:creator>anilchaithu</dc:creator>
      <dc:date>2020-07-21T21:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog</title>
      <link>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/510416#M8265</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Are you trying to forward wineventlog from remote server to splunk using universal forwarder? - Yes, and it has been working fine. Suddenly I stopped seeing WinEventLog sending data to the main index. What could be a reason and how can I troubleshoot? Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 12:25:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/510416#M8265</guid>
      <dc:creator>Jeronimo317</dc:creator>
      <dc:date>2020-07-22T12:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog</title>
      <link>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/510422#M8266</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223950"&gt;@Jeronimo317&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;which Technical Add-On are you using?&lt;/P&gt;&lt;P&gt;See in the inputs.conf if there's an index (usually wineventlog).&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 12:41:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/510422#M8266</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-22T12:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog</title>
      <link>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/510442#M8267</link>
      <description>&lt;P&gt;Hi gcusello, I am not sure what do you mean by which Technical Add-on?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 13:27:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/510442#M8267</guid>
      <dc:creator>Jeronimo317</dc:creator>
      <dc:date>2020-07-22T13:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog</title>
      <link>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/510445#M8268</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223950"&gt;@Jeronimo317&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;did you created your own inputs.conf or did you take the Splunk_TA_Windows to take the logs from wineventlog?&lt;/P&gt;&lt;P&gt;Index is usually assigned in inputs.conf, so you should see in the active inputs.conf what's the index assignment.&lt;/P&gt;&lt;P&gt;From your answer I suppose that you didn't used the TA but the web gui inputs configuration; if this is your situation, see in the inputs configuration [Settings -- Inputs] what's the index assignment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 13:38:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/510445#M8268</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-22T13:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog</title>
      <link>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/511096#M8279</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/204579"&gt;@anilchaithu&lt;/a&gt;&amp;nbsp;, thank you for your help I figured out the issue. Turned out that the index was not specifically set in the input.conf and by default the ingest was going to main as oppose to wineventlog. Seems to be OK now. Thanks again&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 12:20:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/511096#M8279</guid>
      <dc:creator>Jeronimo317</dc:creator>
      <dc:date>2020-07-27T12:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog</title>
      <link>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/511101#M8280</link>
      <description>&lt;P&gt;Good!&lt;/P&gt;&lt;P&gt;If your isse was solved, please accept the answer for the other people of the Community.&lt;/P&gt;&lt;P&gt;Ciao and Next Time!&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 12:33:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/WinEventLog/m-p/511101#M8280</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-27T12:33:32Z</dc:date>
    </item>
  </channel>
</rss>

