Getting Data In

Help with Windows Print Server admin log

tomtom0030
Loves-to-Learn

The print server OS is Windows Server 2019

 

I would like to get PrintService-Admin log to Splunk.

I tried the following in the input.conf of Universal Forwarder in print server.

[WinEventLog://Microsoft-Windows-PrintService/Admin]
disabled = 0
index = winps

Which is found in https://community.splunk.com/t5/Getting-Data-In/Microsoft-Windows-PrintService-Operational-Logs/m-p/...

But I cannot find any events from the index.

 

The log is enabled in the server, which is under Applications and Services Logs > Microsoft > Windows > PrintService

tomtom0030_0-1720122496496.png

tomtom0030_1-1720122510865.png

 

I also tried to set the data input from web console to monitor the log file in folder: C:\Windows\System32\winevt\Logs

 

With RegEx:

Microsoft\-Windows\-PrintService.+\.evtx

So i can get

Microsoft-Windows-PrintService%4Admin.evtx

AND

Microsoft-Windows-PrintService%4Operational.evtx

 

But also, no event is shown for the index.

Hope somebody can help with this.

Thanks

 

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. You can't get events directly from evtx files so don't even bother trying 😉 But seriously - UF uses system calls to query eventlog channels so no direct reading from the files is involved.

2. Are you getting _any_ eventlogs from this UF?

3. What user does your splunkd.exe run with? Did you adjust ACLs on the eventlogs? Did you grant the user with proper privileges?

0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...