Getting Data In

Why is splunkd log not pulling the Windows event logs for application and security?

heats
Explorer

I pulled this from the splunkd log. I finally have my Windows 2016 box checking into Splunk. I can see it in Forwarder Management however it is not pulling the Windows Event logs for Application and Security.

Here's my inputs.conf:

[default]
host = ctw-ansible0101

[WinEventLog://Application]
disabled = 0
index = heats-test
[WinEventLog://Security]
disabled = 0
index = heats-test

[monitor://$SPLUNK_HOME\var\log\splunk\splunkd.log]
index = heats-test

04-25-2017 11:26:49.240 -0400 WARN IndexerService - Received event for unconfigured/disabled/deleted index=heats-test with source="source::C:\Program Files\Splunk\var\log\splunk\splunkd.log" host="host::ctw-ansible0101" sourcetype="sourcetype::splunkd". So far received events from 1 missing index(es).

This index is in Splunk so I'm not sure why it says it's unconfigured/disabled/deleted. Any ideas?

Labels (2)
0 Karma

harsaheb123
Observer

Search for the event log you are looking for in the search text box.

For eg:- if you want to search an event log with the name "TEST" search for-

TEST source="WinEventLog:Application"

in the Splunk search text box

0 Karma

heats
Explorer

Still no joy or logs coming in. No longer seeing any errors about indexes just not receiving the logs. I put an event into the Application log - can't find it in Splunk still.

0 Karma

adonio
Ultra Champion

Hello heats,
looks like your index is not configured correctly,
will recommend to use underscore and not hyphen for indexes names (and in splunk in general)
also check out this document for troubleshooting:
http://docs.splunk.com/Documentation/Splunk/6.5.3/Troubleshooting/Cantfinddata

0 Karma

heats
Explorer

Created new heats_test index and made the changes in inputs.conf. Made a new event in the application log and restarted the splunk service. Still no joy - no logs coming in to the heats_test index. The good news is I don't see that error anymore in the splunkd log.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you have a distributed Splunk system, make sure the heats-test index is defined on all indexers, not just the search head.

---
If this reply helps you, Karma would be appreciated.
0 Karma

heats
Explorer

We only have one indexer.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...