<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows Events with Null Message in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Windows-Events-with-Null-Message/m-p/88943#M22770</link>
    <description>&lt;P&gt;Splunk is reporting a majority of my windows events are being returned with "Null" in the message field.  However, When I review the same message on the server on which the message occurred, there is information in the eventdata field.   &lt;/P&gt;</description>
    <pubDate>Tue, 26 Apr 2011 14:05:15 GMT</pubDate>
    <dc:creator>richnavis</dc:creator>
    <dc:date>2011-04-26T14:05:15Z</dc:date>
    <item>
      <title>Windows Events with Null Message</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Windows-Events-with-Null-Message/m-p/88943#M22770</link>
      <description>&lt;P&gt;Splunk is reporting a majority of my windows events are being returned with "Null" in the message field.  However, When I review the same message on the server on which the message occurred, there is information in the eventdata field.   &lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2011 14:05:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Windows-Events-with-Null-Message/m-p/88943#M22770</guid>
      <dc:creator>richnavis</dc:creator>
      <dc:date>2011-04-26T14:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Events with Null Message</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Windows-Events-with-Null-Message/m-p/88944#M22771</link>
      <description>&lt;P&gt;I think this is related to this bug:&lt;BR /&gt;
The Message field is not extracted and is therefore missing from imported Windows event log file (.evt) data. (SPL-24947) (the list of known issues are located &lt;A href="http://www.splunk.com/base/Documentation/latest/ReleaseNotes/Knownissues"&gt;here&lt;/A&gt;)&lt;/P&gt;

&lt;P&gt;From what I understand that this is a troublesome bug which resides mostly on Microsoft's side.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2011 14:46:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Windows-Events-with-Null-Message/m-p/88944#M22771</guid>
      <dc:creator>Brian_Osburn</dc:creator>
      <dc:date>2011-04-26T14:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Events with Null Message</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Windows-Events-with-Null-Message/m-p/88945#M22772</link>
      <description>&lt;P&gt;Figured it out.. Needed to restart SplunkD to establish new connection to windows servers.&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2011 14:40:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Windows-Events-with-Null-Message/m-p/88945#M22772</guid>
      <dc:creator>richnavis</dc:creator>
      <dc:date>2011-05-02T14:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Events with Null Message</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Windows-Events-with-Null-Message/m-p/88946#M22773</link>
      <description>&lt;P&gt;Could also restart WMI service on the windows servers to reset the WMI connection&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2011 16:53:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Windows-Events-with-Null-Message/m-p/88946#M22773</guid>
      <dc:creator>richnavis</dc:creator>
      <dc:date>2011-05-09T16:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Events with Null Message</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Windows-Events-with-Null-Message/m-p/88947#M22774</link>
      <description>&lt;P&gt;To restart the WMI Service:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;net stop winmgmt 
net start winmgmt 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="https://msdn.microsoft.com/en-us/library/aa826517%28v=vs.85%29.aspx"&gt;Link&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2015 09:13:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Windows-Events-with-Null-Message/m-p/88947#M22774</guid>
      <dc:creator>bjoernjensen</dc:creator>
      <dc:date>2015-02-10T09:13:30Z</dc:date>
    </item>
  </channel>
</rss>

