Getting Data In

After a change to inputs.conf to get Windows security event logs, why am I getting error "Failed to checkpoint for channel='security'"?

abovebeyond
Communicator

Hello,

I've changed some whitelist parameters in the inputs.conf file to index Windows security event logs, however, I'm seeing the error:

message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - WinEventMon::processLogChannel: Failed to checkpoint for channel='security'

What is the problem?

Thanks!

1 Solution

abovebeyond
Communicator

i think i fixed it, stopped the service for few second and start it again. Thanks !

View solution in original post

abovebeyond
Communicator

i think i fixed it, stopped the service for few second and start it again. Thanks !

bmacias84
Champion

Does your forwarder run as different user other than system? If so you may have permission issue. Other wise post a input stanza.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...