Hello everyone,
I have been receiving the follow message:
Splunk could not get the description for this event. Either the component that raises this event is not installed on your local computer or the installation is corrupt. FormatMessage error: Got the following information from this event: <Shows the information>,
the source is WinEventLog:Application.
But not from all the host have the same issue.
And I don't know how to fix it.
The version that I used is 7.3.5.
Thanks in advance.
You want to checkout workaround
https://community.splunk.com/t5/Knowledge-Management/Solutions-quot-Splunk-could-not-get-the-descrip...
There's an extensive troubleshooting section way down at the bottom of this answer:
Keep going down until you get to the last post on that one, it's long and will involve work, but should help a lot in isolating this problem.
Remember to toss a karma at that post if it helps!
-Rich