Getting Data In

ٍError "Splunk could not get the description for this event " in the message field

fahimeh
Explorer

Hello,
Some of the logs coming from the Windows Universal Forwarder to Splunk show the following error in the message field for certain events:
"Splunk could not get the description for this event."

I have reviewed
[https://community.splunk.com/t5/Getting-Data-In/Why-quot-FormatMessage-error-quot-appears-in-indexed...
, but it doesn't solve the issue, as this problem only occurs for a few specific events at specific times. I am using Splunk version 9.2.

What could be the issue?

Labels (2)
0 Karma

fahimeh
Explorer

hi @gcusello 

No, I use the classic format

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @fahimeh ,

are you using xml or classif format?

if xml, try using the classic format adding renderXML=0 to the inputs.conf.

Ciao.

Giuseppe

0 Karma

fahimeh
Explorer

hi @gcusello 

No, I use the classic format

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @fahimeh ,

this is a Splunk maintenad add-on, so you can open a case to Splunk Support.

Without accessing your system it's hard to identify the issue.

Ciao.

Giuseppe

0 Karma

fahimeh
Explorer

pastedImage.jpg

 

The error message is generated only for these specific event codes

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @fahimeh ,

are you sure that it's a Splunk issue and not a Windows issue?

Anyway, open a case to Splunk Support.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Monitoring MariaDB and MySQL

In a previous post, we explored monitoring PostgreSQL and general best practices around which metrics to ...

Financial Services Industry Use Cases, ITSI Best Practices, and More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Splunk Federated Analytics for Amazon Security Lake

Thursday, November 21, 2024  |  11AM PT / 2PM ET Register Now Join our session to see the technical ...