Feedback
Got feedback? We want it! Submit your comments and suggestions for our community here.

Windows log ingestion issue

test1022
New Member

As stated in the subject, we are currently unable to ingest Windows logs.

It appears that the installation has been completed, and that the Splunk Add-on for Windows has been installed on both the Universal Forwarder and the Splunk platform. However, no data is being ingested at all.

We would like you to check the current state to determine what is happening.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @test1022 

Are you able to see the _internal logs for your Universal Forwarder (UF) host in your Splunk deployment? This would indicate that it is succesfully connecting to your indexer(s), if this is the case then I would validate that the Windows app inputs are enabled on your UF. 

From the UF run a btool to check that disabled is not false/0 for the desired Windows inputs:

$SPLUNK_HOME/bin/splunk cmd btool inputs list --debug

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This forum is for questions and answers about Splunk products.  It's not a consultation service.  If you need someone to look at your system then Splunk offers On Demand Services and Professional Services for that.

Have you enabled inputs in the Splunk Add-on for Windows on the UF?  Did you restart the forwarder after enabling the inputs?  How did you determine no data is being ingested?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...