Getting Data In

ٍError "Splunk could not get the description for this event " in the message field

fahimeh
Explorer

Hello,
Some of the logs coming from the Windows Universal Forwarder to Splunk show the following error in the message field for certain events:
"Splunk could not get the description for this event."

I have reviewed
[https://community.splunk.com/t5/Getting-Data-In/Why-quot-FormatMessage-error-quot-appears-in-indexed...
, but it doesn't solve the issue, as this problem only occurs for a few specific events at specific times. I am using Splunk version 9.2.

What could be the issue?

Labels (2)
0 Karma

hrawat
Splunk Employee
Splunk Employee
0 Karma

fahimeh
Explorer

hi @gcusello 

No, I use the classic format

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @fahimeh ,

are you using xml or classif format?

if xml, try using the classic format adding renderXML=0 to the inputs.conf.

Ciao.

Giuseppe

0 Karma

fahimeh
Explorer

hi @gcusello 

No, I use the classic format

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @fahimeh ,

this is a Splunk maintenad add-on, so you can open a case to Splunk Support.

Without accessing your system it's hard to identify the issue.

Ciao.

Giuseppe

0 Karma

fahimeh
Explorer

pastedImage.jpg

 

The error message is generated only for these specific event codes

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @fahimeh ,

are you sure that it's a Splunk issue and not a Windows issue?

Anyway, open a case to Splunk Support.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Exciting News: The AppDynamics Community Joins Splunk!

Hello Splunkers,   I’d like to introduce myself—I’m Ryan, the former AppDynamics Community Manager, and I’m ...

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...