Getting Data In

Windows event log collection randomly stops

abonuccelli_spl
Splunk Employee
Splunk Employee

I am collecting WinEventLog (not using WMI) data using a Universal Forwarder, Heavy Forwarder or full Splunk Instance, I'm using versions prior to 5.0.5, and data collection randomly stops; the host I'm collecting data from is surely not idle and generating a fair amount of WinEvents, I am not using WMI. I can see _internal/audit data coming in. A restart fixes the problem, however this happens again at some point.

I have enabled DEBUG and seeing this after the issue happens...

DEBUG WinEventLogInputProcessor - main-thread: Waiting for Windows Event Log with timeout=10000.
DEBUG WinEventLogInputProcessor - main-thread: Waiting for Windows Event Log with timeout=10000.
DEBUG WinEventLogInputProcessor - main-thread: Waiting for Windows Event Log with timeout=10000.
DEBUG WinEventLogInputProcessor - main-thread: Waiting for Windows Event Log with timeout=10000.

Tags (2)
0 Karma
1 Solution

abonuccelli_spl
Splunk Employee
Splunk Employee

There is a bug (SPL-64915 - WinEventLog InputChannel stop collecting data due to constant timeout.)
This is fixed in version 5.0.5 and greater.

View solution in original post

abonuccelli_spl
Splunk Employee
Splunk Employee

There is a bug (SPL-64915 - WinEventLog InputChannel stop collecting data due to constant timeout.)
This is fixed in version 5.0.5 and greater.

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...