Getting Data In

ٍError "Splunk could not get the description for this event " in the message field

fahimeh
Explorer

Hello,
Some of the logs coming from the Windows Universal Forwarder to Splunk show the following error in the message field for certain events:
"Splunk could not get the description for this event."

I have reviewed
[https://community.splunk.com/t5/Getting-Data-In/Why-quot-FormatMessage-error-quot-appears-in-indexed...
, but it doesn't solve the issue, as this problem only occurs for a few specific events at specific times. I am using Splunk version 9.2.

What could be the issue?

Labels (2)
0 Karma

hrawat
Splunk Employee
Splunk Employee
0 Karma

fahimeh
Explorer

hi @gcusello 

No, I use the classic format

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @fahimeh ,

are you using xml or classif format?

if xml, try using the classic format adding renderXML=0 to the inputs.conf.

Ciao.

Giuseppe

0 Karma

fahimeh
Explorer

hi @gcusello 

No, I use the classic format

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @fahimeh ,

this is a Splunk maintenad add-on, so you can open a case to Splunk Support.

Without accessing your system it's hard to identify the issue.

Ciao.

Giuseppe

0 Karma

fahimeh
Explorer

pastedImage.jpg

 

The error message is generated only for these specific event codes

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @fahimeh ,

are you sure that it's a Splunk issue and not a Windows issue?

Anyway, open a case to Splunk Support.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...