Getting Data In

Monitoring using "WinPrintMon", why are some universal forwarders reporting "ProcessRefresh: Failed ProcessRefresh: error = '0x800706ba'. Restart."?

bravon
Communicator

I monitor using "WinPrintMon" on several hundred servers - 17 of those servers gives this error-message at each poll:

04-14-2015 12:05:09.990 +0200 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"" splunk-winPrintMon - monitorHost::ProcessRefresh: Failed ProcessRefresh: error = '0x800706ba'. Restart.

It's always the same 17 servers - any tips?

[WinPrintMon://printer]
type = printer
interval = 600
baseline = 1
disabled = 0
index = windows

[WinPrintMon://job]
type = job
interval = 600
baseline = 1
disabled = 0
index = windows

[WinPrintMon://driver]
type = driver
interval = 600
baseline = 1
disabled = 0
index = windows

[WinPrintMon://port]
type = port
interval = 600
baseline = 1
disabled = 0
index = windows
0 Karma
1 Solution

bravon
Communicator

The solution was painfully simple - the "Print service" was disabled on the servers. Enabled the print service and the errors stopped.

View solution in original post

lmakonnen2
New Member

how did you enable it?

0 Karma

bravon
Communicator

The solution was painfully simple - the "Print service" was disabled on the servers. Enabled the print service and the errors stopped.

lmakonnen2
New Member

I have same issues and the problem is that I don't hove access to the servers reporting this error. Can you share how you enabled the services.

0 Karma

robert_miller
Path Finder

Did you ever figure out the answer to this? I am seeing the same errors appear on our servers.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...