Getting Data In

Why Windows Event Logs show "Splunk could not get the description for this event. Either ..." in message field in Splunk 6.1.2?

harald_leitl
Path Finder

Hello,

I'm using splunk universal forwarder version 6.1.2 on Windows Servers to index EventLogs. The Events are indexed (indexer version 6.1.2), however the message field contains following message:

Splunk could not get the description for this event. Either the component that raises this event is not installed on your local computer or the installation is corrupt.

In the Event Viewer on the Windows Server the message field is displayed correctly. I couldn't identify a specific EventID nor Server version, it happens on win server 2003 and also 2008r2. However it seems to happen mostly in Security and Application Log.

If found an article that describes the problem, however it addressed a bug in 4.3.x

http://answers.splunk.com/answers/66436/splunk-could-not-get-the-description-for-this-event-4-3-2-un...

Any ideas or suggestions? Could it be the same bug?

thanks!

1 Solution

aivarson_splunk
Splunk Employee
Splunk Employee
0 Karma

michaelstillmun
Explorer

I am using UF 6.2.3 and I started to see this error message as well.

For me, it started when I added two strings to the inputs.conf stanza on our Windows Domain Controllers (2008 R2).

I deployed a new configs that added the following lines to the inputs.conf file located on the forwarder at:

C:\Program Files\SplunkUniversalForwarder\etc\apps\local\inputs.conf

I added the evt dns and dc names.

[WinEventLog://Security]
disabled = 0  
start_from = oldest
current_only = 0
%|250214524_4|%
...
evt_dc_name  = <domain name>
evt_dns_name =<domain name
... 

I was trying to see if it would help on SID EVENT translations, but really just caused the event messages to report the description error.

Once I remove the lines from the stanza and restarted the splunk service, I started to received the correctly formatted events.

I also seen some users install an updated version afer 6.2.x of the UF install over there current one with success. I suspect the new install just overwrote the inputs.conf and now they now longer see the issue, but i am not certain.

/Michael

0 Karma

aivarson_splunk
Splunk Employee
Splunk Employee
0 Karma

cyndiback
Path Finder

Same issue
OS: Windows Server 2012
Universal forwarder 6.1.2.2213098
Source: WinEventLog:Security and WinEventLog:Application

0 Karma

patterc
Path Finder

Does this error message actually indicate anything BAD on the host or the server? I'm seeing thousands of occurrences of this issue in my environment but I still get my logs and don't seem to have any issues.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...