Getting Data In

Unable to index Microsoft-Windows-PrintService/Operational

mcmiked97
Engager

Hello,

I would like to index all print events generated on Windows Server 2012 Event log. The log is located under Windows Logs, Applications and Services, Microsoft, Windows, PrintService, Operational (and Admin).

I installed a Universal Forwarder on the print server then tried to view logs on my indexer, and the only Available Logs are the standard ones. If I look at Data Inputs for Local Log File Collection, the PrintService logs are available.

Here are the contents of my local\inputs.conf

[default]
host = PS-MAINOFFICE2

[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]
disabled = 0

[WinEventLog://Microsoft-Windows-PrintService/Admin]
disabled = 0

[WinEventLog://Microsoft-Windows-PrintService/Operational]
disabled = 0

Here's what shows in my splunkd.log on the print server:

02-27-2014 13:18:45.767 -0500 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - WELCheckPoint::saveCheckpointStr: Unable to open checkpoint file='C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\microsoft-windows-printservice/operational' for write
    02-27-2014 13:18:45.767 -0500 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - WinEventLogChannel::saveBookMark: Failed to save checkpoint_file='C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\microsoft-windows-printservice/operational' for channel='microsoft-windows-printservice/operational'
    02-27-2014 13:18:45.767 -0500 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - WinEventMon::processLogChannel: Failed to checkpoint for channel='microsoft-windows-printservice/operational'

Am I missing something somewhere?

Thanks,
Mike

mcmiked97
Engager

I don't know what happened, but the problem seemed to have fixed itself. I'm seeing print events now. A couple things to clarify:

  1. Make sure the PrintService Operational (and/or Admin) event logs are enabled in Windows.
  2. Ensure that the inputs.conf file you modified is in C:\Program Files\SplunkUniversalForwarder\etc\system\local
  3. Restart the Splunk Universal Forwarder service after any modifications to the file.

FWIW, my Splunk Forwarder service runs under LocalSystem account, not a specific user account. Are you seeing the same errors I saw in my Splunk logs?

0 Karma

TobiasBoone
Communicator

Looking for a solution to this as well.

0 Karma

selim
Path Finder

Did you get a solution for this? I'm facing the same error and can not figure out what's going on.

thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...