Getting Data In

Unable to index Microsoft-Windows-PrintService/Operational

mcmiked97
Engager

Hello,

I would like to index all print events generated on Windows Server 2012 Event log. The log is located under Windows Logs, Applications and Services, Microsoft, Windows, PrintService, Operational (and Admin).

I installed a Universal Forwarder on the print server then tried to view logs on my indexer, and the only Available Logs are the standard ones. If I look at Data Inputs for Local Log File Collection, the PrintService logs are available.

Here are the contents of my local\inputs.conf

[default]
host = PS-MAINOFFICE2

[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]
disabled = 0

[WinEventLog://Microsoft-Windows-PrintService/Admin]
disabled = 0

[WinEventLog://Microsoft-Windows-PrintService/Operational]
disabled = 0

Here's what shows in my splunkd.log on the print server:

02-27-2014 13:18:45.767 -0500 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - WELCheckPoint::saveCheckpointStr: Unable to open checkpoint file='C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\microsoft-windows-printservice/operational' for write
    02-27-2014 13:18:45.767 -0500 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - WinEventLogChannel::saveBookMark: Failed to save checkpoint_file='C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\microsoft-windows-printservice/operational' for channel='microsoft-windows-printservice/operational'
    02-27-2014 13:18:45.767 -0500 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - WinEventMon::processLogChannel: Failed to checkpoint for channel='microsoft-windows-printservice/operational'

Am I missing something somewhere?

Thanks,
Mike

mcmiked97
Engager

I don't know what happened, but the problem seemed to have fixed itself. I'm seeing print events now. A couple things to clarify:

  1. Make sure the PrintService Operational (and/or Admin) event logs are enabled in Windows.
  2. Ensure that the inputs.conf file you modified is in C:\Program Files\SplunkUniversalForwarder\etc\system\local
  3. Restart the Splunk Universal Forwarder service after any modifications to the file.

FWIW, my Splunk Forwarder service runs under LocalSystem account, not a specific user account. Are you seeing the same errors I saw in my Splunk logs?

0 Karma

TobiasBoone
Communicator

Looking for a solution to this as well.

0 Karma

selim
Path Finder

Did you get a solution for this? I'm facing the same error and can not figure out what's going on.

thanks

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...