Hello,
Some of the logs coming from the Windows Universal Forwarder to Splunk show the following error in the message field for certain events:
"Splunk could not get the description for this event."
I have reviewed
[https://community.splunk.com/t5/Getting-Data-In/Why-quot-FormatMessage-error-quot-appears-in-indexed...
, but it doesn't solve the issue, as this problem only occurs for a few specific events at specific times. I am using Splunk version 9.2.
What could be the issue?
hi @gcusello
No, I use the classic format
Hi @fahimeh ,
are you using xml or classif format?
if xml, try using the classic format adding renderXML=0 to the inputs.conf.
Ciao.
Giuseppe
hi @gcusello
No, I use the classic format
Hi @fahimeh ,
this is a Splunk maintenad add-on, so you can open a case to Splunk Support.
Without accessing your system it's hard to identify the issue.
Ciao.
Giuseppe
The error message is generated only for these specific event codes
Hi @fahimeh ,
are you sure that it's a Splunk issue and not a Windows issue?
Anyway, open a case to Splunk Support.
Ciao.
Giuseppe