Getting Data In

Splunk Universal Forwarder not forwarding Windows Event Log : Application

jyotishman22
New Member

I am using the universal forwarder to forward Windows event logs - Security, System and Application. The security and system are forwarded just fine but the Application logs are not being forwarded. The corresponding log entry in the splunkd file says:
"Finished processing existing Windows Event Log 'Application': total_events='0' with empty_msg='0'."

Could you please suggest how I should go about debugging this issue?

Tags (1)
0 Karma

jyotishman22
New Member

I cleared the event log files and restarted Splunk and that did the trick, I have been receiving the logs since then. Thanks!

0 Karma

mship
Path Finder

Couple of basic questions...

Did you check to see if the application event log on the local machine has any data?

Did you move/create new indexes?

mship
Path Finder

The outputs.conf file is unique to forwarders and it defines how forwarders send data to receivers. Check that to make sure that it is configure properly...must do this through the CLI. You can also enable the deployment monitor app to further trouble shoot while we try to figure this out. http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Startthedeploymentmonitor

0 Karma

jyotishman22
New Member

I haven't modified the outputs.conf file, if I save the event viewer items to a local file and ask splunk to monitor the local file I get the same message on the splunkd log:

06-05-2012 13:43:40.103 -0400 INFO WinEventLogInputProcessor - main-thread: Finished processing existing Windows Event Log 'C:\Program Files (x86)\EBSCO\SDIAlertService\Logs\temp.evtx': total_events='0' with empty_msg='0'.

However this file is about 12MB in size and contains about 200 events. I installed the UF through the GUI.

0 Karma

mship
Path Finder

What does outputs.conf on the UF read?

0 Karma

jyotishman22
New Member

I am now monitoring the Windows event log directory, the corresponding entry on my inputs.conf file says:

[monitor://C:WindowsSystem32WinevtLogsApplication.evtx]
disabled = false

I can view the entries through the Event Viewer. However these aren't being forwarded by the forwarder, the splunkd log file entry shows:

06-05-2012 13:21:05.665 -0400 INFO WinEventLogInputProcessor - main-thread: Finished processing existing Windows Event Log 'C:WindowsSystem32WinevtLogsApplication.evtx': total_events='0' with empty_msg='0'.

Any suggestions/work arounds would be appreciated.

0 Karma

jyotishman22
New Member

Yes, the application event log has data which I can view through the Event Viewer. The machine is running Windows 2008, I was reading about the alwaysOpenFile option ... would this be applicable in this case?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...