<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No search results from Windows Servers (DC and EXCH) in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584051#M203625</link>
    <description>&lt;P&gt;I know that the official recommended approach is to install UFs everywhere but for the sake of manageability did you consider using Windows Event Forwarding? (provided your windows workstations are in an AD domain).&lt;/P&gt;</description>
    <pubDate>Tue, 08 Feb 2022 07:38:09 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2022-02-08T07:38:09Z</dc:date>
    <item>
      <title>No search results from Windows Servers (DC and EXCH)- what to do next?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583410#M203613</link>
      <description>&lt;P&gt;I recently inherited a newly configured Splunk Enterprise 8 environment after the former admin left. I have a basic user level knowledge of Splunk so I will describe my issue the best I can.&lt;/P&gt;
&lt;P&gt;When we try to search for a specific or wildcard event (ie: print logs) we only receive results from the Linux servers but not the Windows servers. I was suggested to check the .conf files for Windows TA, but I'm not quite sure what I should be looking for within the files. The Splunk documentation site has been helpful, however it doesn't explain why we aren't seeing events. Splunk is installed on RHEL8 and we have installed forwarders on all the servers. I do not know where to go from here. Any assistance is appreciated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*Note: Former admin claimed that the server was fully configured in accordance with DIA's required auditable event list. The server is receiving data however it is not being disseminated properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 14:48:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583410#M203613</guid>
      <dc:creator>MBIT2022</dc:creator>
      <dc:date>2022-02-10T14:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: No event results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583429#M203614</link>
      <description>&lt;P&gt;Please clarify.&amp;nbsp; When you say you don't receive events from Windows servers are you referring to Splunk instances running on Windows or Windows data sources that are indexed in Splunk?&lt;/P&gt;&lt;P&gt;It would help if you could share a sanitized search query or tell us more about how you are searching for events.&amp;nbsp; Linux and Windows can produce very different logs so how you search may determine which logs appear in the results.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 16:09:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583429#M203614</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-02-02T16:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: No event results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583433#M203615</link>
      <description>&lt;P&gt;What I mean is that when I attempt to search for events in the Splunk GUI, it's not returning any results. The only search that really gives me results is an error search, but all the errors trace back to only 3-4 of my servers.&amp;nbsp; At least one is a Linux server and the others are Windows.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 17:14:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583433#M203615</guid>
      <dc:creator>MBIT2022</dc:creator>
      <dc:date>2022-02-02T17:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: No event results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583452#M203616</link>
      <description>There could be defined default index which you are use in unless you are adding index=xyz on you SPL. As &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt; said it helps us if you could write here your spl query.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Wed, 02 Feb 2022 21:37:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583452#M203616</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-02-02T21:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: No event results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583704#M203617</link>
      <description>&lt;P&gt;I'm honestly struggling to understand SPL. But if I try wildcard entries such as *login or *error I receive some results but only from a handful of servers and it's not always what I'm looking for. For other searches, it shows "0 of 2,500,000 events matched" so I know that Splunk is receiving data but for some reason its not letting me search for it. If that makes sense&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 12:04:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583704#M203617</guid>
      <dc:creator>MBIT2022</dc:creator>
      <dc:date>2022-02-04T12:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: No event results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583706#M203618</link>
      <description>&lt;P&gt;Please share the full query, the (sanitized) results, and the expected results.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 12:44:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583706#M203618</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-02-04T12:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: No event results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583708#M203619</link>
      <description>&lt;P&gt;Try doing the introductory free trainings. They are quite well written and give a quick overview of what splunk is and does.&lt;/P&gt;&lt;P&gt;You might do a&lt;/P&gt;&lt;PRE&gt;| tstats count where index=* by index host&lt;/PRE&gt;&lt;P&gt;over a day or week back to see if you have any data and just can't find it.&lt;/P&gt;&lt;P&gt;Oh, and you might be using a user with limited access to indexes.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 12:58:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583708#M203619</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-04T12:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: No event results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583711#M203620</link>
      <description>&lt;P&gt;I ran a "index=*" search for the last week to date and so far it's only returned 46 hosts and 90mil events. Many are duplicate events but it appears that not all the servers and workstations are reporting and/or the forwarder is nor installed or configured properly. I will look into this further. We are also using 2.8.1. Is it absolutely necessary to update to 2.8.4? I ask only because every forwarder will have to be manually updated for the workstations. Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 13:26:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583711#M203620</guid>
      <dc:creator>MBIT2022</dc:creator>
      <dc:date>2022-02-04T13:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: No event results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583717#M203621</link>
      <description>&lt;P&gt;Whereas you should (must?) keep the version consistent within the clustered server environment, you don't have to be so strict about UF&amp;lt;-&amp;gt;"server" consistency. The compatibility matrix is here &lt;A href="https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwardersandindexers" target="_blank"&gt;https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwardersandindexers&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 14:01:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583717#M203621</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-04T14:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: No event results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583727#M203622</link>
      <description>&lt;P&gt;ok thank you&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 14:41:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583727#M203622</guid>
      <dc:creator>MBIT2022</dc:creator>
      <dc:date>2022-02-04T14:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: No search results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583962#M203623</link>
      <description>&lt;P&gt;It appears that we need to install the universal forwarder on every workstation. Is there any easy way to deploy it remotely? We do not have SCCM nor a Altiris license. Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 15:15:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/583962#M203623</guid>
      <dc:creator>MBIT2022</dc:creator>
      <dc:date>2022-02-07T15:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: No search results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584027#M203624</link>
      <description>&lt;P&gt;The UF installation manual has sections about that.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/8.2.4/Forwarder/Installanixuniversalforwarderremotelywithastaticconfiguration" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/8.2.4/Forwarder/Installanixuniversalforwarderremotelywithastaticconfiguration&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/8.2.4/Forwarder/InstallaWindowsuniversalforwarderremotelywithastaticconfiguration" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/8.2.4/Forwarder/InstallaWindowsuniversalforwarderremotelywithastaticconfiguration&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 22:33:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584027#M203624</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-02-07T22:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: No search results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584051#M203625</link>
      <description>&lt;P&gt;I know that the official recommended approach is to install UFs everywhere but for the sake of manageability did you consider using Windows Event Forwarding? (provided your windows workstations are in an AD domain).&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 07:38:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584051#M203625</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-08T07:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: No search results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584089#M203626</link>
      <description>&lt;P&gt;We were trying not to manually install the forwarders so they are installed on just the DCs and Exchange servers (and other servers).&amp;nbsp; We are able to pull information with a generic search but cannot see workstation or user specific information. I feel that either a setting is incorrect on the server or there is something misconfigured in one of the .conf files.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 11:28:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584089#M203626</guid>
      <dc:creator>MBIT2022</dc:creator>
      <dc:date>2022-02-08T11:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: No search results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584092#M203627</link>
      <description>&lt;P&gt;Unfortunately we currently do not have any software deployment tools. My server admin also informed me that GPOs are not working properly so we cannot deploy via GPO. Thank you for the links&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 11:32:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584092#M203627</guid>
      <dc:creator>MBIT2022</dc:creator>
      <dc:date>2022-02-08T11:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: No search results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584096#M203628</link>
      <description>&lt;P&gt;You can't get events from the workstations if you don't have access to that workstation. So you'd have to either have UFs installed on your all workstations (which as you say is impossible in your organization) or configure a WMI-based event retrieval (which might be working for a small set of servers but is really not a good idea for a huge number of workstations).&lt;/P&gt;&lt;P&gt;The alternative is to use Windows Event Forwarding mechanism (a built-in services in AD) which will cause forwarding of the events from the workstations to a designated Windows Server which will store them in Forwarder Events event log. From ther you could just pull them with a single splunk UF.&lt;/P&gt;&lt;P&gt;The downside to this method is that again - you'd need to configure WEF mechanism company-wide (most probably using GPO).&lt;/P&gt;&lt;P&gt;There is no magical way to get the events from the workstations without "touching them".&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 11:43:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584096#M203628</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-08T11:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: No search results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584097#M203629</link>
      <description>&lt;P&gt;Ok, I'll try to install forwarders on some workstations today and see if anything changes. For reference, when installing the forwarder should I be choosing Local or Domain under Configuration Options? I updated the forwarder on the DCs last week and couldn't find any set answer on which to choose. Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 11:48:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584097#M203629</guid>
      <dc:creator>MBIT2022</dc:creator>
      <dc:date>2022-02-08T11:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: No search results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584098#M203630</link>
      <description>&lt;P&gt;Well, it's a relatively complicated topic. In domain environment you'd probably want to run splunk forwarder using a managed service account but that's something you want to discuss with your local admins. The account splunk forwarder runs with has&amp;nbsp; to have certain privileges and permissions (for example, reading event logs). You can run it with Local System account but that might not land very well with your security team.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 12:01:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584098#M203630</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-08T12:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: No search results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584099#M203631</link>
      <description>&lt;P&gt;Ok, I'll look more into it. Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 12:03:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584099#M203631</guid>
      <dc:creator>MBIT2022</dc:creator>
      <dc:date>2022-02-08T12:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: No search results from Windows Servers (DC and EXCH)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584532#M203632</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; I was able to manually install the forwarder on 9 workstations. I am definitely receiving more data but I'm still not seeing the events I need (successful/failed logins, print activity, file/folder modifications). Is there anything that needs to be configured via GPO? I have all servers set to collect and forward event logs. I want to share my .conf files but the network with Splunk is isolated and classified, so it is very difficult to move over data. Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 13:45:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/No-search-results-from-Windows-Servers-DC-and-EXCH-what-to-do/m-p/584532#M203632</guid>
      <dc:creator>MBIT2022</dc:creator>
      <dc:date>2022-02-10T13:45:50Z</dc:date>
    </item>
  </channel>
</rss>

