<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What does yellow boxes/triangles in the search-app and panels with the text &amp;quot;Eventtype 'wineventlog-dns' does not exist or is disabled&amp;quot; (ditto for 'wineventlog-ds') mean? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/What-does-yellow-boxes-triangles-in-the-search-app-and-panels/m-p/281205#M190540</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;We have the following setup:&lt;/P&gt;

&lt;P&gt;Splunk Enterprise Server 6.4.1&lt;BR /&gt;
Windows2008R2, 16 GB Physical Memory, 4 CPU Cores&lt;BR /&gt;
Mode: Standalone&lt;/P&gt;

&lt;P&gt;In all my searches from the Search-app i am getting a "yellow box with an exclamation mark in it", whereas in all the panels in a dashboard there is a "yellow triangle with an exclamation mark in it".&lt;BR /&gt;
In both cases the following text appears whene I click them:&lt;/P&gt;

&lt;P&gt;Eventtype 'wineventlog-dns' does not exist or is disabled.&lt;BR /&gt;
Eventtype 'wineventlog-ds' does not exist or is disabled.&lt;/P&gt;

&lt;P&gt;The searches as such seem to be ok.&lt;/P&gt;

&lt;P&gt;Any suggestions as to where I should start looking?&lt;/P&gt;

&lt;P&gt;Could it have anything to d with these mesaages from teh splunkd.log?&lt;/P&gt;

&lt;P&gt;At restart:&lt;/P&gt;

&lt;P&gt;07-25-2016 18:01:17.613 +0200 INFO  PipelineComponent - Pipeline structuredparsing disabled in default-mode.conf file&lt;BR /&gt;
07-25-2016 18:01:17.691 +0200 INFO  IntrospectionGenerator:resource_usage -   RU_main - I-data gathering (Resource Usage) starting; period=10s&lt;BR /&gt;
07-25-2016 18:01:18.038 +0200 WARN  IntrospectionGenerator:resource_usage -   RU - Failure executing initial system PDH query, status code is -2147481643&lt;BR /&gt;
07-25-2016 18:01:18.038 +0200 WARN  IntrospectionGenerator:resource_usage -   RU - Failure executing initial disk PDH query, status code is -2147481643&lt;BR /&gt;
07-25-2016 18:01:18.038 +0200 INFO  IntrospectionGenerator:resource_usage -   RU_main - I-data gathering (IO Statistics) starting; interval=60s&lt;BR /&gt;
07-25-2016 18:01:18.038 +0200 WARN  IntrospectionGenerator:resource_usage -   RU - Failure executing PDH query, skipping getting iostats data this collection cycle. Status code is -2147481643&lt;/P&gt;

&lt;P&gt;Therafter every minute this:&lt;/P&gt;

&lt;P&gt;07-26-2016 02:15:32.082 +0200 WARN  IntrospectionGenerator:resource_usage -   RU - Failure executing PDH query, skipping getting iostats data this collection cycle. Status code is -2147481643&lt;/P&gt;

&lt;P&gt;Thanks for any help,&lt;BR /&gt;
Kind reagards,&lt;BR /&gt;
Bård Tørustad&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 10:22:10 GMT</pubDate>
    <dc:creator>torustad</dc:creator>
    <dc:date>2020-09-29T10:22:10Z</dc:date>
    <item>
      <title>What does yellow boxes/triangles in the search-app and panels with the text "Eventtype 'wineventlog-dns' does not exist or is disabled" (ditto for 'wineventlog-ds') mean?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-does-yellow-boxes-triangles-in-the-search-app-and-panels/m-p/281205#M190540</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;We have the following setup:&lt;/P&gt;

&lt;P&gt;Splunk Enterprise Server 6.4.1&lt;BR /&gt;
Windows2008R2, 16 GB Physical Memory, 4 CPU Cores&lt;BR /&gt;
Mode: Standalone&lt;/P&gt;

&lt;P&gt;In all my searches from the Search-app i am getting a "yellow box with an exclamation mark in it", whereas in all the panels in a dashboard there is a "yellow triangle with an exclamation mark in it".&lt;BR /&gt;
In both cases the following text appears whene I click them:&lt;/P&gt;

&lt;P&gt;Eventtype 'wineventlog-dns' does not exist or is disabled.&lt;BR /&gt;
Eventtype 'wineventlog-ds' does not exist or is disabled.&lt;/P&gt;

&lt;P&gt;The searches as such seem to be ok.&lt;/P&gt;

&lt;P&gt;Any suggestions as to where I should start looking?&lt;/P&gt;

&lt;P&gt;Could it have anything to d with these mesaages from teh splunkd.log?&lt;/P&gt;

&lt;P&gt;At restart:&lt;/P&gt;

&lt;P&gt;07-25-2016 18:01:17.613 +0200 INFO  PipelineComponent - Pipeline structuredparsing disabled in default-mode.conf file&lt;BR /&gt;
07-25-2016 18:01:17.691 +0200 INFO  IntrospectionGenerator:resource_usage -   RU_main - I-data gathering (Resource Usage) starting; period=10s&lt;BR /&gt;
07-25-2016 18:01:18.038 +0200 WARN  IntrospectionGenerator:resource_usage -   RU - Failure executing initial system PDH query, status code is -2147481643&lt;BR /&gt;
07-25-2016 18:01:18.038 +0200 WARN  IntrospectionGenerator:resource_usage -   RU - Failure executing initial disk PDH query, status code is -2147481643&lt;BR /&gt;
07-25-2016 18:01:18.038 +0200 INFO  IntrospectionGenerator:resource_usage -   RU_main - I-data gathering (IO Statistics) starting; interval=60s&lt;BR /&gt;
07-25-2016 18:01:18.038 +0200 WARN  IntrospectionGenerator:resource_usage -   RU - Failure executing PDH query, skipping getting iostats data this collection cycle. Status code is -2147481643&lt;/P&gt;

&lt;P&gt;Therafter every minute this:&lt;/P&gt;

&lt;P&gt;07-26-2016 02:15:32.082 +0200 WARN  IntrospectionGenerator:resource_usage -   RU - Failure executing PDH query, skipping getting iostats data this collection cycle. Status code is -2147481643&lt;/P&gt;

&lt;P&gt;Thanks for any help,&lt;BR /&gt;
Kind reagards,&lt;BR /&gt;
Bård Tørustad&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:22:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-does-yellow-boxes-triangles-in-the-search-app-and-panels/m-p/281205#M190540</guid>
      <dc:creator>torustad</dc:creator>
      <dc:date>2020-09-29T10:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: What does yellow boxes/triangles in the search-app and panels with the text "Eventtype 'wineventlog-dns' does not exist or is disabled" (ditto for 'wineventlog-ds') mean?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-does-yellow-boxes-triangles-in-the-search-app-and-panels/m-p/281206#M190541</link>
      <description>&lt;P&gt;See answer here, should fix your issue: &lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/433485/message-eventtype-wineventlog-ds-does-not-exist-or.html"&gt;https://answers.splunk.com/answers/433485/message-eventtype-wineventlog-ds-does-not-exist-or.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2016 19:29:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-does-yellow-boxes-triangles-in-the-search-app-and-panels/m-p/281206#M190541</guid>
      <dc:creator>tsweet_splunk</dc:creator>
      <dc:date>2016-07-26T19:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: What does yellow boxes/triangles in the search-app and panels with the text "Eventtype 'wineventlog-dns' does not exist or is disabled" (ditto for 'wineventlog-ds') mean?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-does-yellow-boxes-triangles-in-the-search-app-and-panels/m-p/281207#M190542</link>
      <description>&lt;P&gt;Thanks for your help; I disabled the "splunk_app_windows_infrastructure" - app and the "yellow warnings" went away.&lt;BR /&gt;
I have had this app installed for quite a time (albeit without it working :-)) so this "yellow warning" most likely came after the upgrade to 6.4.1.&lt;/P&gt;

&lt;P&gt;However this message keeps coming in the splund.log:&lt;/P&gt;

&lt;P&gt;07-26-2016 02:15:32.082 +0200 WARN IntrospectionGenerator:resource_usage - RU - Failure executing PDH query, skipping getting iostats data this collection cycle. Status code is -2147481643&lt;/P&gt;

&lt;P&gt;Regards&lt;BR /&gt;
Bård&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:25:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-does-yellow-boxes-triangles-in-the-search-app-and-panels/m-p/281207#M190542</guid>
      <dc:creator>torustad</dc:creator>
      <dc:date>2020-09-29T10:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: What does yellow boxes/triangles in the search-app and panels with the text "Eventtype 'wineventlog-dns' does not exist or is disabled" (ditto for 'wineventlog-ds') mean?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-does-yellow-boxes-triangles-in-the-search-app-and-panels/m-p/281208#M190543</link>
      <description>&lt;P&gt;This started with Windows Infrastructure App V 1.3 that was released last month.  I am guessing you recently upgraded this application as well.  &lt;/P&gt;

&lt;P&gt;The other error message is related to something else if I had to guess.  &lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2016 14:42:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-does-yellow-boxes-triangles-in-the-search-app-and-panels/m-p/281208#M190543</guid>
      <dc:creator>tsweet_splunk</dc:creator>
      <dc:date>2016-07-28T14:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: What does yellow boxes/triangles in the search-app and panels with the text "Eventtype 'wineventlog-dns' does not exist or is disabled" (ditto for 'wineventlog-ds') mean?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-does-yellow-boxes-triangles-in-the-search-app-and-panels/m-p/281209#M190544</link>
      <description>&lt;P&gt;We are here now: "Splunk App for Windows Infrastructure"  version 1.3.0, so you are right - I upgraded it because I have a far more serious problem which I did not think had anything to do with this app, but I upgraded it anyway in the offchance that it did &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2016 17:07:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-does-yellow-boxes-triangles-in-the-search-app-and-panels/m-p/281209#M190544</guid>
      <dc:creator>torustad</dc:creator>
      <dc:date>2016-07-28T17:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: What does yellow boxes/triangles in the search-app and panels with the text "Eventtype 'wineventlog-dns' does not exist or is disabled" (ditto for 'wineventlog-ds') mean?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-does-yellow-boxes-triangles-in-the-search-app-and-panels/m-p/281210#M190545</link>
      <description>&lt;P&gt;I just upgraded from windows infrastructure 1.2 to 1.3 and i'm seeing the ds warning as well, what's the fix?  I have the dns app installed so i'm not getting the dns error only the ds error.&lt;/P&gt;

&lt;P&gt;Eventtype 'wineventlog-ds' does not exist or is disabled&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 20:58:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-does-yellow-boxes-triangles-in-the-search-app-and-panels/m-p/281210#M190545</guid>
      <dc:creator>mtime24</dc:creator>
      <dc:date>2016-08-16T20:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: What does yellow boxes/triangles in the search-app and panels with the text "Eventtype 'wineventlog-dns' does not exist or is disabled" (ditto for 'wineventlog-ds') mean?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-does-yellow-boxes-triangles-in-the-search-app-and-panels/m-p/281211#M190546</link>
      <description>&lt;P&gt;I created an eventtypes.conf in /splunk_app_windows_infrastructure/local/ on my search head and indexer containing this:&lt;/P&gt;

&lt;P&gt;[wineventlog-dns]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
search = sourcetype=WinEventLog:DNS Server&lt;/P&gt;

&lt;P&gt;Problem solved, for now. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:08:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-does-yellow-boxes-triangles-in-the-search-app-and-panels/m-p/281211#M190546</guid>
      <dc:creator>mrgibbon</dc:creator>
      <dc:date>2020-09-29T11:08:20Z</dc:date>
    </item>
  </channel>
</rss>

