Getting Data In

Data could not be written:

bogdan_nicolesc
Communicator

I have searched high and low for an answer here and on web, but seems that i can't find a suitable answer.

 

Did anyone got this error while tring to get data in?

 

 

Data could not be written: /nobody/search/inputs/WinEventLog://System/start_from: oldest

 

 

I played a bit with System log of windows and at first i used the "Local event log collection" but then changed my mind and changed it to "Remote event log collections".

But yet again, first time, using "Local event log collection" i got older data too, second time using "Remote event log collections" i get only newer data.

What can i do to reset it? In what file should i look?

Thank you.

Labels (3)
0 Karma

bogdan_nicolesc
Communicator

Did all that and i get the same error.

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @bogdan_nicolesc,

In order to reset the checkpoint you should delete below file on Windows host and restart Universal Forwarder service.

C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\System
If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

bogdan_nicolesc
Communicator

Would a pc reboot would do?

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...