All Apps and Add-ons

Inconsistent windows event monitoring using splunk.

naagaraj
Engager

Hi Team,

We are working on a solution to monitor the utilization time of resources on their machines. We have about 1000 machines where Splunk forwarders are installed. These forwarders are pushing data to a central splunk instance. 

The issue that now we are facing is that the event codes are getting missed sometimes. For eg after an unlock(4801) there should be a lock(4800). But we are getting two simultaneous unlock event code(4801) without lock. This is sending our calculation of utilization time for a toss.

 

Below is the input stanza in the splunk forwarders.

[WinEventLog://Security]
checkpointInterval = 5
current_only = 0
disabled = 0
index = test_events
start_from = oldest
whitelist = 4624,4634,4800,4801

 

We are unable to figure out this issue for the past week. can someone pls help us out on this.

Many Thanks,

Naagaraj SV

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Cultivate Your Career Growth with Fresh Splunk Training

Growth doesn’t just happen—it’s nurtured. Like tending a garden, developing your Splunk skills takes the right ...

Introducing a Smarter Way to Discover Apps on Splunkbase

We’re excited to announce the launch of a foundational enhancement to Splunkbase: App Tiering.  Because we’ve ...