Deployment Architecture

Universal forwarder connecting to heavy forwarder but not sending windows event logs

jgorman_THG
Explorer

Hello,

I have a client with a Windows 2008r2 server running a universal forwarder and set to forward Windows Event, Application, and Security logs to a heavy forwarder. From there the client is using SplunkCloud.

In SplunkCloud, I can see the machine connecting, but it doesn't seem to be sending any information.

I can see the following information:

08-23-2016 01:24:27.191 +0000 INFO Metrics - group=per_host_thruput, series="Machine_Name", kbps=0.031723, eps=0.387102, kb=0.983398, ev=12, avg_age=0.916667, max_age=1
host = idx1.client.splunkcloud.com source = /opt/splunk/var/log/splunk/metrics.log sourcetype = splunkd

The client does not believe it is a GPO problem.

I do not have direct access to the machine But I will be asking the client for the input.conf and output.conf files tomorrow.

Can someone point me in the right direction for solving this problem?

Thanks,

0 Karma

jgorman_THG
Explorer

HI Guys!

Thanks for you input. It was a stupid simple mistake, my colleague who set the system-up didn't create a "wineventlog" index, and me being a newby didn't know to look for it.

Thanks for your input!

0 Karma

sk314
Builder

Could it be a timestamp issue? Did you try searching over all-time to see if you see any results. This might sound silly...but It has happened many times.

0 Karma

rharrisssi
Path Finder

I think we need to first see inputs.conf and outputs.conf and go from there. Instead of asking the client for specific files, ask for the entire etc directory in the UF in-case we have more questions.

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...