Alerting

Splunk could not get the description for this event - Splunk 5..0.2

imoskal
Engager

Hi!
Splunk is installed on the server Windows 2008 R2. It indexes the events that collecting the Windows Event Log Collector. Some events Splunk can not display:
Message=Splunk could not get the description for this event. Either the component that raises this event is not installed on your local computer or the installation is corrupt.
FormatMessage error: The locale specific resource for the desired message is not present.
Event Viewer displays all of the events correctly.
Thanks in advance for any help.

Tags (1)
0 Karma

kristian_kolb
Ultra Champion

Things that show up in the EventViewer correctly should be available to the locally installed Splunk instance.

If you are sure that this specific message is completely visible in EventViewer, but not in Splunk, you should file a support case. There is no currently known bug that manifests itself like this.

Describe the OS version, Splunk version, what the source of the data is, i.e. which application/eventcode that work, and which don't.

Hope this helps,

K

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...