All Apps and Add-ons

Splunk App for Windows Infrastructure: Why are WinEventLog configurations not indexing any data?

amithhegde
New Member

I have the Windows Infrastructure app installed on a Windows machine. The monitor stanza and the powershell scripts are working fine, but the Winevent logs with the following config are not indexing any data.

[WinEventLog:DFS Replication]
 disabled=0
 sourcetype="WinEventLog:DFS Replication"
 index=winevents
 queue=parsingQueue

 # Application and Services Logs - Directory Service

 [WinEventLog:Directory Service]
 disabled=0
 sourcetype="WinEventLog:Directory Service"
 index=winevents
 queue=parsingQueue

 # Application and Services Logs - File Replication Service

 [WinEventLog:File Replication Service]
 disabled=0
 sourcetype="WinEventLog:File Replication Service"
 index=winevents
 queue=parsingQueue

Please guide me where am I going wrong?

0 Karma

Richfez
SplunkTrust
SplunkTrust

Two semi-general suggestions:

If it's installed on the local machine, is that local machine a Domain Controller?

You do have a "winevents" index on the indexer this gets sent to, right? If not, create that. I believe I had a problem where that app didn't create one of the indexes, though I don't recall which one. This could be your problem.

0 Karma

Richfez
SplunkTrust
SplunkTrust

Well, something I noticed and I have no idea if it's a problem or not, but all my DCs have their various sourcetypes set with no spaces in it.

For instance, on the one I checked, C:\Program Files\SplunkUniversalForwarder\etc\apps\TA-DomainController-NT6\default\inputs.conf says:

[WinEventLog://File Replication Service]
disabled=0
sourcetype=WinEventLog:File-Replication-Service
index=wineventlog
queue=parsingQueue

Try changing them to dashes and not spaces in those stanza and restart the UF?

0 Karma

amithhegde
New Member

Hi Rich,

Thanks for replyin, yes I have the "winevents" index created, and the machine I want to gt events from is not a local machine. But i have deployed the DomainController App on the machine in question.

Kindly let me know if I am missing something. Any suggestions on this would be really helpful.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...