I'm using splunk universal forwarder version 6.1.2 on Windows Servers to index EventLogs. The Events are indexed (indexer version 6.1.2), however the message field contains following message:
Splunk could not get the description for this event. Either the component that raises this event is not installed on your local computer or the installation is corrupt.
In the Event Viewer on the Windows Server the message field is displayed correctly. I couldn't identify a specific EventID nor Server version, it happens on win server 2003 and also 2008r2. However it seems to happen mostly in Security and Application Log.
If found an article that describes the problem, however it addressed a bug in 4.3.x
Any ideas or suggestions? Could it be the same bug?
I am using UF 6.2.3 and I started to see this error message as well.
For me, it started when I added two strings to the inputs.conf stanza on our Windows Domain Controllers (2008 R2).
I deployed a new configs that added the following lines to the
inputs.conf file located on the forwarder at:
I added the evt dns and dc names.
[WinEventLog://Security] disabled = 0 start_from = oldest current_only = 0 %|250214524_4|% ... evt_dc_name = <domain name> evt_dns_name =<domain name ...
I was trying to see if it would help on SID EVENT translations, but really just caused the event messages to report the description error.
Once I remove the lines from the stanza and restarted the splunk service, I started to received the correctly formatted events.
I also seen some users install an updated version afer 6.2.x of the UF install over there current one with success. I suspect the new install just overwrote the
inputs.conf and now they now longer see the issue, but i am not certain.
Does this error message actually indicate anything BAD on the host or the server? I'm seeing thousands of occurrences of this issue in my environment but I still get my logs and don't seem to have any issues.