Getting Data In

Monitoring using "WinPrintMon", why are some universal forwarders reporting "ProcessRefresh: Failed ProcessRefresh: error = '0x800706ba'. Restart."?

bravon
Communicator

I monitor using "WinPrintMon" on several hundred servers - 17 of those servers gives this error-message at each poll:

04-14-2015 12:05:09.990 +0200 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"" splunk-winPrintMon - monitorHost::ProcessRefresh: Failed ProcessRefresh: error = '0x800706ba'. Restart.

It's always the same 17 servers - any tips?

[WinPrintMon://printer]
type = printer
interval = 600
baseline = 1
disabled = 0
index = windows

[WinPrintMon://job]
type = job
interval = 600
baseline = 1
disabled = 0
index = windows

[WinPrintMon://driver]
type = driver
interval = 600
baseline = 1
disabled = 0
index = windows

[WinPrintMon://port]
type = port
interval = 600
baseline = 1
disabled = 0
index = windows
0 Karma
1 Solution

bravon
Communicator

The solution was painfully simple - the "Print service" was disabled on the servers. Enabled the print service and the errors stopped.

View solution in original post

lmakonnen2
New Member

how did you enable it?

0 Karma

bravon
Communicator

The solution was painfully simple - the "Print service" was disabled on the servers. Enabled the print service and the errors stopped.

lmakonnen2
New Member

I have same issues and the problem is that I don't hove access to the servers reporting this error. Can you share how you enabled the services.

0 Karma

robert_miller
Path Finder

Did you ever figure out the answer to this? I am seeing the same errors appear on our servers.

0 Karma
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...