Feedback
Got feedback? We want it! Submit your comments and suggestions for our community here.

Windows log ingestion issue

test1022
New Member

As stated in the subject, we are currently unable to ingest Windows logs.

It appears that the installation has been completed, and that the Splunk Add-on for Windows has been installed on both the Universal Forwarder and the Splunk platform. However, no data is being ingested at all.

We would like you to check the current state to determine what is happening.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @test1022 

Are you able to see the _internal logs for your Universal Forwarder (UF) host in your Splunk deployment? This would indicate that it is succesfully connecting to your indexer(s), if this is the case then I would validate that the Windows app inputs are enabled on your UF. 

From the UF run a btool to check that disabled is not false/0 for the desired Windows inputs:

$SPLUNK_HOME/bin/splunk cmd btool inputs list --debug

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This forum is for questions and answers about Splunk products.  It's not a consultation service.  If you need someone to look at your system then Splunk offers On Demand Services and Professional Services for that.

Have you enabled inputs in the Splunk Add-on for Windows on the UF?  Did you restart the forwarder after enabling the inputs?  How did you determine no data is being ingested?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...