All Apps and Add-ons

apps for Windows infrastructure

qhmassc
Explorer

I am running the following versions of Splunk and supporting apps for Windows infrastructure on Linux RHEL 6.8:
Splunk Enterprise 7.2.1
Splunk App for Windows Infrastructure 1.5.0
Windows Add-on 5.0.1

Client side Is Windows 2008R2 SP1 installed with UF, and Windows Add-on 5.0.1 was deployed from deployment server.

If I go to Splunk App for Windows Infrastructure do the search I can see data is getting in, like index="wineventlog", I can see a lot events.
But if I select Windows > Windows Overview, I only can see "0 Hosts", I also can see the list of sources, sourceTypes and hosts, how can I see the Overview?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...