Getting Data In

Help with PrintService log ingestion

bteele
New Member

I'm trying to ingest Windows PrintService logs into our distributed environment. I've got a dedicated index, and have built an app with an inputs.conf with the following:

[WinEventLog://Microsoft-Windows-PrintService/Admin]
index = winprintlog
disabled = 0
start_from = oldest

The app is distributed via server class from our deployment server. I've confirmed the print servers have the app and the config file. I've restarted Splunk on the Deployment server, and manually restarted several forwarder services, but none of the servers are sending log data.

I don't know that there's been any new events since I deployed (they seem rare enough) but this same config was used on a custom Windows Powershell log app and it pulled all of the historical logs as well, of which there are plenty for the PrintService.

What am I missing?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...