Getting Data In

Why Windows Event Logs show "Splunk could not get the description for this event. Either ..." in message field in Splunk 6.1.2?

harald_leitl
Path Finder

Hello,

I'm using splunk universal forwarder version 6.1.2 on Windows Servers to index EventLogs. The Events are indexed (indexer version 6.1.2), however the message field contains following message:

Splunk could not get the description for this event. Either the component that raises this event is not installed on your local computer or the installation is corrupt.

In the Event Viewer on the Windows Server the message field is displayed correctly. I couldn't identify a specific EventID nor Server version, it happens on win server 2003 and also 2008r2. However it seems to happen mostly in Security and Application Log.

If found an article that describes the problem, however it addressed a bug in 4.3.x

http://answers.splunk.com/answers/66436/splunk-could-not-get-the-description-for-this-event-4-3-2-un...

Any ideas or suggestions? Could it be the same bug?

thanks!

1 Solution

aivarson_splunk
Splunk Employee
Splunk Employee
0 Karma

michaelstillmun
Explorer

I am using UF 6.2.3 and I started to see this error message as well.

For me, it started when I added two strings to the inputs.conf stanza on our Windows Domain Controllers (2008 R2).

I deployed a new configs that added the following lines to the inputs.conf file located on the forwarder at:

C:\Program Files\SplunkUniversalForwarder\etc\apps\local\inputs.conf

I added the evt dns and dc names.

[WinEventLog://Security]
disabled = 0  
start_from = oldest
current_only = 0
%|250214524_4|%
...
evt_dc_name  = <domain name>
evt_dns_name =<domain name
... 

I was trying to see if it would help on SID EVENT translations, but really just caused the event messages to report the description error.

Once I remove the lines from the stanza and restarted the splunk service, I started to received the correctly formatted events.

I also seen some users install an updated version afer 6.2.x of the UF install over there current one with success. I suspect the new install just overwrote the inputs.conf and now they now longer see the issue, but i am not certain.

/Michael

0 Karma

aivarson_splunk
Splunk Employee
Splunk Employee
0 Karma

cyndiback
Path Finder

Same issue
OS: Windows Server 2012
Universal forwarder 6.1.2.2213098
Source: WinEventLog:Security and WinEventLog:Application

0 Karma

patterc
Path Finder

Does this error message actually indicate anything BAD on the host or the server? I'm seeing thousands of occurrences of this issue in my environment but I still get my logs and don't seem to have any issues.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...