All Apps and Add-ons

Splunk App for Windows infrastructure data not showing in app



I currently have Splunk app for Windows Infrastructure installed and have a windows 2008 server setup with a universal forwarder with the Splunk_TA_windows add-on installed. I see the windows server logs being indexed on the Splunk 6.0 server. But it's not populating inside the app.

help please.

Path Finder

You have to go into the XML view for the dashboards and look at what searches are run to populate the dashboard.

They may rely on the sourcetype or index defined in the inputs.conf or something more abstract like an eventtype.


Can you elaborate? I am having a similar problem. The only inputs.conf I edited for the setup was the one for the LDAP app. Is there another one?

0 Karma


I figured out what i was doing wrong. i some how grabbed the wrong inputs.conf file and edited that one. i found the correct one and the data started to flow into the app.

anyhow thanks for the response.


I don't know much about the app, but I would guess that it is expecting the Windows data to be stored in a particular index. (index=os perhaps?)
If the data is stored elsewhere (like index=main for example), you will be able to see the data, but it won't appear in the Windows app dashboards, etc.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...