Getting Data In

Data could not be written:

bogdan_nicolesc
Communicator

I have searched high and low for an answer here and on web, but seems that i can't find a suitable answer.

 

Did anyone got this error while tring to get data in?

 

 

Data could not be written: /nobody/search/inputs/WinEventLog://System/start_from: oldest

 

 

I played a bit with System log of windows and at first i used the "Local event log collection" but then changed my mind and changed it to "Remote event log collections".

But yet again, first time, using "Local event log collection" i got older data too, second time using "Remote event log collections" i get only newer data.

What can i do to reset it? In what file should i look?

Thank you.

Labels (3)
0 Karma

bogdan_nicolesc
Communicator

Did all that and i get the same error.

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @bogdan_nicolesc,

In order to reset the checkpoint you should delete below file on Windows host and restart Universal Forwarder service.

C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\System
If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

bogdan_nicolesc
Communicator

Would a pc reboot would do?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...