Getting Data In

Splunk forwarders failing to send some of the Windows application Event logs for some devices

Gayathirikuppus
New Member

Why are Splunk forwarders failing to send some of the Windows application Event logs for some devices? We are using Splunk_TA_windows add on for ingesting the window event viewer logs into splunk. We do not observer any Error in the internal log but found some Warning Message as mentioned below:

3/19/18
11:33:47.270 PM
03-19-2018 23:33:47.270 -0400 WARN DateParserVerbose - Failed to parse timestamp. Defaulting to timestamp of previous event (Mon Mar 19 23:33:47 2018). Context: source::WMI:Services|host::XXXXXX|WMI:Services|1
host = XXXXXX source = C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd.log sourcetype = splunkd
3/19/18
10:50:29.897 PM
03-19-2018 22:50:29.897 -0400 WARN DateParserVerbose - Failed to parse timestamp. Defaulting to timestamp of previous event (Mon Mar 19 22:50:29 2018). Context: source::WMI:SessionProcess|host::XXXXXX|WMI:SessionProcess|1
host = XXXXXX source = C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd.log sourcetype = splunkd
3/19/18
10:48:36.030 PM
03-19-2018 22:48:36.030 -0400 WARN DateParserVerbose - Failed to parse timestamp. Defaulting to timestamp of previous event (Mon Mar 19 22:48:35 2018). Context: source::WMI:SessionProcess|host::XXXXXX|WMI:SessionProcess|1
host = XXXXXX source = C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd.log sourcetype = splunkd
3/19/18
10:45:09.527 PM
03-19-2018 22:45:09.527 -0400 WARN DateParserVerbose - Failed to parse timestamp. Defaulting to timestamp of previous event (Mon Mar 19 22:45:09 2018). Context: source::WMI:SessionProcess|host::XXXXXX|WMI:SessionProcess|1
host = XXXXXX source = C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd.log sourcetype = splunkd

Please find the inputs.conf:
[WinEventLog://Application]
disabled = 0
start_from = oldest
current_only = 0
checkpointInterval = 5
index = wineventlog
renderXml=false
_meta=fromserver::Y

Is there any other configuration that i needed to check? What am i missing here to check?

Tags (1)
0 Karma

Gayathirikuppus
New Member

We have some many eventcode but only few of them are getting ingested into splunk

0 Karma

adonio
Ultra Champion

on one hand, your inputs refer to the forwarder monitor, on the other hand, your error suggests WMI inputs.
might have some conflict there, can you verify the entire inputs.conf? do you have inputs.conf in /etc/system/local as well?

0 Karma

Gayathirikuppus
New Member

Yeah the inputs.conf that I have shared is from local folder. Where do I need to check for WMI inputs for the discrepancy.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...