Getting Data In

Monitoring Windows Event Logs

keio_splunk
Splunk Employee
Splunk Employee

Windows Event Log files (.evtx) monitoring stop working after a while and the Splunk universal forwarder has to be restarted to start data collection again.

Here is the [monitor] stanza configured to monitor the Windows Event Log files (.evtx):
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerActivity.evtx]
disabled = 0
index = WinEvent

[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerManagement.evtx]
disabled = 0
index = WinEvent

0 Karma
1 Solution

keio_splunk
Splunk Employee
Splunk Employee

Universal forwarder will not poll for inputs for window events when specifying the [monitor] if interval is not specified.
i.e.
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerActivity.evtx]
disabled = 0
index = WinEvent

Solution 1: Specify an interval value for the [monitor] stanza:
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerActivity.evtx]
interval = 60
disabled = 0
index = WinEvent

Solution 2: Use [WinEventLog] stanza for Windows Event Log files monitoring:
[WinEventLog://VisualSVNServerActivity]
disabled = 0
index = WinEvent

Refer to Monitor Windows event log data.

View solution in original post

keio_splunk
Splunk Employee
Splunk Employee

Universal forwarder will not poll for inputs for window events when specifying the [monitor] if interval is not specified.
i.e.
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerActivity.evtx]
disabled = 0
index = WinEvent

Solution 1: Specify an interval value for the [monitor] stanza:
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerActivity.evtx]
interval = 60
disabled = 0
index = WinEvent

Solution 2: Use [WinEventLog] stanza for Windows Event Log files monitoring:
[WinEventLog://VisualSVNServerActivity]
disabled = 0
index = WinEvent

Refer to Monitor Windows event log data.

Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...