Getting Data In

Universal Forwarder only sends monitored log file once per restart...

nabeel652
Builder

I have a universal forwarder installed on my Print Server (Windows 2012 R2). I used WinPrintMon but it is giving some funny results. However, I am able to pull out printer logs through pointing directly to the file c:\windows\system32\winevt\logs\microsoft-windows-printer%4operational. However, the forwarder only sends once the logs when restarted. After that it will not send any logs until restarted.

0 Karma

acharlieh
Influencer

Why are you using a monitor stanza instead of a WinEventLog stanza similar to: http://answers.splunk.com/answers/124859/unable-to-index-microsoft-windows-printservice-operational....

richgalloway
SplunkTrust
SplunkTrust

What are your inputs.conf settings?

---
If this reply helps you, Karma would be appreciated.
0 Karma

nabeel652
Builder

Thanks buddy, adding WinEventLog stanza solved my problem Cheers 🙂

0 Karma

nabeel652
Builder
[monitor://c:\windows\system32\winevt\logs\Microsoft-Windows-PrintService%4Admin]
disabled=false
index=printmon

I've also tried with MonitorNoHandle but in that case the forwarder doesn't send data at all.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...