Getting Data In

Why am I getting this WMI DCOM error?

maverick
Splunk Employee
Splunk Employee

Currently, I'm using WMI to pull WinEvents from 17 Windows running on VMs. They are each the exact same and were built off the exact same VM template.

However, I am receiving an Application error WinEvent in my Splunk for 2 out of the 17 hosts that says DCOM is unable to communicate using the configured protocol, it looks like this:


Message=DCOM was unable to communicate with the computer <foo.bar.com> using any of the configured protocols.

Anyone ever see this before and/or know why this could be happening, especially since all the VMs are the same?

BTW, I know about using a Splunk Forwarder instead of WMI, but I just want to know if anyone can confirm this as a bug or some kind of Microsoft limitation or issue, or just a config issue maybe, etc.

Tags (4)
0 Karma

hexx
Splunk Employee
Splunk Employee

I'm not sure I see this as an issue related to Splunk. The message appears to only impact some DCOM communication problem between two Windows hosts. I am not aware that Splunk leverages the DCOM service when collecting WMI inputs. Is there any misbehavior actually observed in Splunk?

hexx
Splunk Employee
Splunk Employee

I have to say, I remain unconvinced that this is Splunk-related. Innocent until proven guilty 🙂

0 Karma

offwire
New Member

Since Maverick posted this question on my behalf, there is no misbehavior actually observed in Splunk. I have added about 15 servers (all Windows 2008 R2, all built from the same VMWARE Server Template) but the Splunk Server (also built from this template) is only throwing this for 2 of the servers, which just of course happen to be my application servers. I am kind of at a loss for why there is a communication problem only between these 2 servers and the Splunk server.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...