Getting Data In

Data could not be written:

bogdan_nicolesc
Communicator

I have searched high and low for an answer here and on web, but seems that i can't find a suitable answer.

 

Did anyone got this error while tring to get data in?

 

 

Data could not be written: /nobody/search/inputs/WinEventLog://System/start_from: oldest

 

 

I played a bit with System log of windows and at first i used the "Local event log collection" but then changed my mind and changed it to "Remote event log collections".

But yet again, first time, using "Local event log collection" i got older data too, second time using "Remote event log collections" i get only newer data.

What can i do to reset it? In what file should i look?

Thank you.

Labels (3)
0 Karma

bogdan_nicolesc
Communicator

Did all that and i get the same error.

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @bogdan_nicolesc,

In order to reset the checkpoint you should delete below file on Windows host and restart Universal Forwarder service.

C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\System
If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

bogdan_nicolesc
Communicator

Would a pc reboot would do?

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...