on the weekend i messed up the Splunk Installation whith the try to move the Database to a different place. But because i'm just starting using splunk a quick reinstall got it back working... well all except Remote eventlog Collection (via WMI)
I created a new Data Input selected only the Application log on teh remote server, but nothing happens.
I checked with Splunk\bin>splunk-wmi -wql "select * from win32_service" -namespace
\server\root\cimv2 if teh WMI Permissions are right and data came in just fine.
Then i tried it with renaming the wmi_checkpoint file (to force a reindex), but even after a restart nothing happens.