All Apps and Add-ons

Event Monitoring dashboard not showing events

jeremyhagand61
Communicator

Hi,

I've installed and configured this app (v6.0) in a test environment with logs from three Windows servers being indexed into the "wineventlog" index. I can see the events being indexed, Event Monitoring dashboard isn't showing any events.

The input lookup which is supposed to be populating the "Log Name" field isn't returning any results.

When I go to "Tools and Settings > Customise Features' I see that the "Event Monitoring" feature is not selected. I have selected it and clicked Save, but it keeps going back to unticked.

How can I troubleshoot this?

I have run the selection under Tools and Settings to generate the lookups and restarted Splunk

Splunk version 7.3.1
Splunk App for Windows Infra: 1.5.2
Splunk TA Windows: 6.0

Cheers,
Jeremy.

0 Karma
1 Solution

jeremyhagand61
Communicator

I managed to fix this by changing the renderXml=true to false in every WinEventLog stanza of the inputs.conf.

This is documented here:
https://docs.splunk.com/Documentation/MSApp/1.5.2/MSInfra/DownloadandconfiguretheSplunkAdd-onforWind...

All the wineventlog inputs (Windows, AD, and DNS) will have renderXml=true (Xml Format) by default. Make it false for all WinEventLog Inputs as XML data is not supported.

But it is very easy to miss. After I modified the inputs.conf and redistributed it I regenerated the lookups (Tools and Setting > Build Lookups) and all is happy.

View solution in original post

jeremyhagand61
Communicator

I managed to fix this by changing the renderXml=true to false in every WinEventLog stanza of the inputs.conf.

This is documented here:
https://docs.splunk.com/Documentation/MSApp/1.5.2/MSInfra/DownloadandconfiguretheSplunkAdd-onforWind...

All the wineventlog inputs (Windows, AD, and DNS) will have renderXml=true (Xml Format) by default. Make it false for all WinEventLog Inputs as XML data is not supported.

But it is very easy to miss. After I modified the inputs.conf and redistributed it I regenerated the lookups (Tools and Setting > Build Lookups) and all is happy.

teak421
Path Finder

This happened to me as well. Nice catch!

I wish that the inputs.conf file that comes with WindowsTA would have the correct defaults. Boy, that would save a ton of time!

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...