Getting Data In

Why is splunkd log not pulling the Windows event logs for application and security?

heats
Explorer

I pulled this from the splunkd log. I finally have my Windows 2016 box checking into Splunk. I can see it in Forwarder Management however it is not pulling the Windows Event logs for Application and Security.

Here's my inputs.conf:

[default]
host = ctw-ansible0101

[WinEventLog://Application]
disabled = 0
index = heats-test
[WinEventLog://Security]
disabled = 0
index = heats-test

[monitor://$SPLUNK_HOME\var\log\splunk\splunkd.log]
index = heats-test

04-25-2017 11:26:49.240 -0400 WARN IndexerService - Received event for unconfigured/disabled/deleted index=heats-test with source="source::C:\Program Files\Splunk\var\log\splunk\splunkd.log" host="host::ctw-ansible0101" sourcetype="sourcetype::splunkd". So far received events from 1 missing index(es).

This index is in Splunk so I'm not sure why it says it's unconfigured/disabled/deleted. Any ideas?

Labels (2)
0 Karma

harsaheb123
Observer

Search for the event log you are looking for in the search text box.

For eg:- if you want to search an event log with the name "TEST" search for-

TEST source="WinEventLog:Application"

in the Splunk search text box

0 Karma

heats
Explorer

Still no joy or logs coming in. No longer seeing any errors about indexes just not receiving the logs. I put an event into the Application log - can't find it in Splunk still.

0 Karma

adonio
Ultra Champion

Hello heats,
looks like your index is not configured correctly,
will recommend to use underscore and not hyphen for indexes names (and in splunk in general)
also check out this document for troubleshooting:
http://docs.splunk.com/Documentation/Splunk/6.5.3/Troubleshooting/Cantfinddata

0 Karma

heats
Explorer

Created new heats_test index and made the changes in inputs.conf. Made a new event in the application log and restarted the splunk service. Still no joy - no logs coming in to the heats_test index. The good news is I don't see that error anymore in the splunkd log.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you have a distributed Splunk system, make sure the heats-test index is defined on all indexers, not just the search head.

---
If this reply helps you, Karma would be appreciated.
0 Karma

heats
Explorer

We only have one indexer.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...