Getting Data In

Missing "Message" field

wnyricsplunk
Explorer

We are moving away from using Windows Event Collection to installing the Universal Forwarder on as many Windows machines as we can. I ran into an interesting issue that I don't know how to resolve.
Event 1646, when collected using WEC and then forwarded to Splunk shows this information, which doesn't appear if the same event is sent directly by the UF.

wnyricsplunk_0-1650645921382.png


I copied the stanza used by the UF on the WEC server and deployed it to the machine where the event is generated but I am still not seeing the "extra" data when not using WEC. What am I missing? (Something easy, no doubt). Seems as though I don't see the "Message" field when the event is collected by the UF.

Thanks in advance.

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...