Getting Data In

Is there an event limit for Windows event log ingestion?

azooju
Engager

I have a Splunk Forwarder running on Windows 2012 and I'm monitoring a share with archived .evtx files from other Windows servers. I discovered that Splunk was ingesting most small event logs (less than 1092 KB) but skipped larger files with events numbering in the thousands. While examining the _internal index within Splunk Enterprise, it was seeing and processing the large files, however, the total events always equaled zero. If I opened the .evtx file on a Windows computer and exported 256 events, the max it allowed me to export at a time, to a new .evtx file, Splunk would see, process the right number of events and ingest the file without any issue.

Update: Further troubleshooting has revealed that the Windows security event log is the only one with this problem. Application and system logs ingest with events numbering in the thousands with no problem. I have a workaround in place to export security logs every 5 minutes. Since this keeps events to around 500 or less per file, Splunk processes the files with the correct number of events.

0 Karma
1 Solution

azooju
Engager

Solution: Working with Splunk support, it was determined that this issue was related to a bug in the version 6.5.1 Universal Forwarder. It has been fixed in 6.5.2.

View solution in original post

0 Karma

azooju
Engager

Solution: Working with Splunk support, it was determined that this issue was related to a bug in the version 6.5.1 Universal Forwarder. It has been fixed in 6.5.2.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...