<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to resolve high increase in forwarders reporting errors, including &amp;quot;Failed to checkpoint&amp;quot; for channel='security'? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-high-increase-in-forwarders-reporting-errors/m-p/438869#M124892</link>
    <description>&lt;P&gt;Getting the same ERROR messages randomly on Windows 2016 servers with forwarders on 7.3.3.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Apr 2020 08:52:21 GMT</pubDate>
    <dc:creator>splunk68</dc:creator>
    <dc:date>2020-04-16T08:52:21Z</dc:date>
    <item>
      <title>How to resolve high increase in forwarders reporting errors, including "Failed to checkpoint" for channel='security'?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-high-increase-in-forwarders-reporting-errors/m-p/438868#M124891</link>
      <description>&lt;P&gt;We discovered that in early April, around the 7th, we had a HUGE increase in forwarders reporting this error:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - WinEventLogChannel::init: Failed to checkpoint for channel='security'
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;UL&gt;
&lt;LI&gt;It's showing up on Windows 7, Windows 10, Server 2012, Server 2016 machines&lt;/LI&gt;
&lt;LI&gt;Most of our forwarders are &lt;STRONG&gt;7.1.2&lt;/STRONG&gt; but we have a few older versions out there.&lt;/LI&gt;
&lt;LI&gt;Most of the hosts I've found with this error are Windows 10&lt;/LI&gt;
&lt;LI&gt;No consistency in terms of OS or Forwarder versions where this error is showing up&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Also, come to find out, this appears to correlate with events being missed from the Windows Event Security Logs and not being forwarded properly.&lt;/P&gt;
&lt;P&gt;The ONLY thing that happened around when this seemed to spread like wildfire was Windows patches were deployed in our environment.&lt;/P&gt;
&lt;P&gt;Has anyone else seen this issue?&lt;/P&gt;
&lt;P&gt;The search we run to identify them is this if anyone wants to take a look to see if they have the errors as well:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;index=_internal sourcetype=splunkd AND ERROR AND Security AND "Failed to checkpoint" AND log_level=ERROR 
| stats count by host
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;We have a case open with Splunk, but the suggested fixes do not seem to be resolving the errors.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 17:59:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-high-increase-in-forwarders-reporting-errors/m-p/438868#M124891</guid>
      <dc:creator>jcleary47</dc:creator>
      <dc:date>2020-06-08T17:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve high increase in forwarders reporting errors, including "Failed to checkpoint" for channel='security'?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-high-increase-in-forwarders-reporting-errors/m-p/438869#M124892</link>
      <description>&lt;P&gt;Getting the same ERROR messages randomly on Windows 2016 servers with forwarders on 7.3.3.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 08:52:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-high-increase-in-forwarders-reporting-errors/m-p/438869#M124892</guid>
      <dc:creator>splunk68</dc:creator>
      <dc:date>2020-04-16T08:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve high increase in forwarders reporting errors, including "Failed to checkpoint" for channel='security'?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-high-increase-in-forwarders-reporting-errors/m-p/438870#M124893</link>
      <description>&lt;P&gt;No update?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 18:04:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-high-increase-in-forwarders-reporting-errors/m-p/438870#M124893</guid>
      <dc:creator>morethanyell</dc:creator>
      <dc:date>2020-06-03T18:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve high increase in forwarders reporting errors, including "Failed to checkpoint" for channel=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-high-increase-in-forwarders-reporting-errors/m-p/526521#M148602</link>
      <description>&lt;P&gt;I am having the same issue repeatedly in our Win'16 environment. Anyone found the cure yet?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 19:19:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-high-increase-in-forwarders-reporting-errors/m-p/526521#M148602</guid>
      <dc:creator>vanvan</dc:creator>
      <dc:date>2020-10-26T19:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve high increase in forwarders reporting errors, including "Failed to checkpoint" for channel=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-high-increase-in-forwarders-reporting-errors/m-p/528759#M149283</link>
      <description>&lt;P&gt;converting UF to use service account seems to have fixed it for me. So if that's not possible at least you know that its a permissions issue with localsystem.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 23:59:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-high-increase-in-forwarders-reporting-errors/m-p/528759#M149283</guid>
      <dc:creator>CarsonZa</dc:creator>
      <dc:date>2020-11-09T23:59:21Z</dc:date>
    </item>
  </channel>
</rss>

