<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No more Event Logs from Client's in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/No-more-Event-Logs-from-Client-s/m-p/102029#M182924</link>
    <description>&lt;P&gt;What i have to check on clients? Clients didnt have a splunkd.log?! :D.&lt;BR /&gt;
And on Splunk i have 2 errors:&lt;/P&gt;

&lt;P&gt;03-27-2012 15:09:18.524 +0200 ERROR splunk-perfmon - PerfmonHelper::enumObjectByNameEx: PdhEnumObjectItems failed for 'Memory' with (0xc0000bb8): Das angegebene Objekt wurde nicht im System gefunden.&lt;/P&gt;

&lt;P&gt;03-27-2012 15:13:53.764 +0200 ERROR ExecProcessor - message from "C:\Programme\Splunk\bin\splunk-wmi.exe" WMI - Error occurred while trying to retrieve results from a WMI query (error="Der Remoteprozeduraufruf ist fehlgeschlagen und wurde nicht ausgeführt." HRESULT=800706BF) (\servername\root\cimv2: Select PercentProcessorTime,PercentUserTime from Win32_PerfFormattedData_PerfOS_Processor where Name = "_Total")&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 11:34:53 GMT</pubDate>
    <dc:creator>Rhuen</dc:creator>
    <dc:date>2020-09-28T11:34:53Z</dc:date>
    <item>
      <title>No more Event Logs from Client's</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-more-Event-Logs-from-Client-s/m-p/102027#M182922</link>
      <description>&lt;P&gt;Hy,&lt;/P&gt;

&lt;P&gt;i dont know why, but since 5 days i become no more Event Logs from Client PC's (Windows XP).&lt;/P&gt;

&lt;P&gt;When i remote connect to this PC's i see new Events, but Splunk become nothing.&lt;BR /&gt;
Can i see anywhere why?.&lt;/P&gt;

&lt;P&gt;From all Servers i become the logs all the time, only client pc's stop this since 5 days, and i dont know why.&lt;/P&gt;

&lt;P&gt;greets.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2012 12:42:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-more-Event-Logs-from-Client-s/m-p/102027#M182922</guid>
      <dc:creator>Rhuen</dc:creator>
      <dc:date>2012-03-27T12:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: No more Event Logs from Client's</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-more-Event-Logs-from-Client-s/m-p/102028#M182923</link>
      <description>&lt;P&gt;Have you checked the splunkd.log on both server and client?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2012 13:06:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-more-Event-Logs-from-Client-s/m-p/102028#M182923</guid>
      <dc:creator>jgedeon120</dc:creator>
      <dc:date>2012-03-27T13:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: No more Event Logs from Client's</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-more-Event-Logs-from-Client-s/m-p/102029#M182924</link>
      <description>&lt;P&gt;What i have to check on clients? Clients didnt have a splunkd.log?! :D.&lt;BR /&gt;
And on Splunk i have 2 errors:&lt;/P&gt;

&lt;P&gt;03-27-2012 15:09:18.524 +0200 ERROR splunk-perfmon - PerfmonHelper::enumObjectByNameEx: PdhEnumObjectItems failed for 'Memory' with (0xc0000bb8): Das angegebene Objekt wurde nicht im System gefunden.&lt;/P&gt;

&lt;P&gt;03-27-2012 15:13:53.764 +0200 ERROR ExecProcessor - message from "C:\Programme\Splunk\bin\splunk-wmi.exe" WMI - Error occurred while trying to retrieve results from a WMI query (error="Der Remoteprozeduraufruf ist fehlgeschlagen und wurde nicht ausgeführt." HRESULT=800706BF) (\servername\root\cimv2: Select PercentProcessorTime,PercentUserTime from Win32_PerfFormattedData_PerfOS_Processor where Name = "_Total")&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:34:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-more-Event-Logs-from-Client-s/m-p/102029#M182924</guid>
      <dc:creator>Rhuen</dc:creator>
      <dc:date>2020-09-28T11:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: No more Event Logs from Client's</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-more-Event-Logs-from-Client-s/m-p/102030#M182925</link>
      <description>&lt;P&gt;I would check client event logs since you are collecting with WMI.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2012 13:26:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-more-Event-Logs-from-Client-s/m-p/102030#M182925</guid>
      <dc:creator>jgedeon120</dc:creator>
      <dc:date>2012-03-27T13:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: No more Event Logs from Client's</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-more-Event-Logs-from-Client-s/m-p/102031#M182926</link>
      <description>&lt;P&gt;I was now change the configuration from "Computername" to there IP-Adress and now i become reports...hm...i must check this the next few days.&lt;/P&gt;

&lt;P&gt;Other Question, how can i do a dashboard with manually Computernames?&lt;BR /&gt;
When i do a event log dashboard i use:&lt;/P&gt;

&lt;P&gt;source="WMI:WinEventLog:&lt;EM&gt;" ComputerName="&lt;/EM&gt;"  | stats count count(eval(Type="Warnung")) as warnings count(eval(Type="Fehler")) as errors by host&lt;/P&gt;

&lt;P&gt;But we have MAC-Adress as Computername, i see only "FFC00..." "FF00..." and so on, how must i change the search command that i have costum Names for the restults?&lt;BR /&gt;
FFCC00 = Computer1&lt;BR /&gt;
FF00 = Computer2 and so on.&lt;/P&gt;

&lt;P&gt;greets.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Mar 2012 10:24:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-more-Event-Logs-from-Client-s/m-p/102031#M182926</guid>
      <dc:creator>Rhuen</dc:creator>
      <dc:date>2012-03-28T10:24:06Z</dc:date>
    </item>
  </channel>
</rss>

