Seeing this weird problem after upgrading a forwarder on a Windows server from 5.x to 6.3.2
After the upgrade, the Windows event log entries are showing in Splunk without the description/details. Before the upgrade, the description of the event was showing up. Below is an example. The message part is empty in Splunk, but it is there on the source server.