All Apps and Add-ons

Why are Windows event log fields not extracting properly in our set up?

adossant
New Member

We are using WMI to send Windows event logs to a Windows UF with Windows-TA installed/configured from deployment server. For the most part this is working as it should. However, we are finding an issue that occurs across multiple servers for various application and system event logs entries where field extraction is not occurring properly. On the UF events viewer, Windows Logs/Forwarded events, the event log fields/entries appear properly. However, when we do a search the fields are not there.

We took one of the Windows servers and installed the UF and Windows-TA app on it. In this set up, the fields for the same event log entry extract properly and are available in a search.

We've looked at a lot of conf files and no luck as of yet. Ideas?

0 Karma

OldManEd
Builder

Adossant,
Were you able to figure this one out yet? I believe I'm seeing the same kind of issue with my instance.
~Ed

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...