Getting Data In

Windows event logs, Linux server

FloydATC
Explorer

I'm running my trial Splunk indexer on a linux host and already collecting data from switches, VMware hosts, firewalls, SAN and a few other interesting systems.

I have configured "Receiving" on the server to listen on port 9997.

This morning I installed the Universal Forwarder on a Windows 2008 R2 server and selected all the Event Logs for forwarding. TCP ports 8089 and 9997 are open on the server side and I can see TCP traffic using tcpdump. The Windows host appears under "Forwarder Management", Phone Home says "a few seconds ago" so I have every reason to believe the communication is working properly.

However, searching for the IP address or hostname of the Windows shows no matches, neither does any search for strings that appear in the event log as seen using Windows' own event log viewer.

I also chose to forward the contents of a single directory where the backup agent produces its log files. Searching for strings that appear in those log files also comes up empty.

What am I missing?

0 Karma
1 Solution

lukejadamec
Super Champion

Check the splunkd log on the windows system for errors. It is probably best to restart splunk on the windows system, so you can see the inputs initialize in the log.
Also, if you run the restart from the cmd window then you see if there are errors in start up, but the cmd window must be "run as administrator" on w2k8.

View solution in original post

FloydATC
Explorer

Thanks for pointing me in the right direction 🙂 The log file seems to indicate that splunk was quite busy transferring files from the selected directory. Judging from the log, after about 30 minutes or so it appears to have settled down and I can now search the Event Log messages as expected.

0 Karma

lukejadamec
Super Champion

Check the splunkd log on the windows system for errors. It is probably best to restart splunk on the windows system, so you can see the inputs initialize in the log.
Also, if you run the restart from the cmd window then you see if there are errors in start up, but the cmd window must be "run as administrator" on w2k8.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Drivers: How We're Streaming Real-Time F1 Telemetry Directly into Splunk ...

Data Drivers: Every Lap Tells a Story The Spectacle Two F1 racing sims go head-to-head on the .conf26 show ...

Data Management Digest – July 2026

  Welcome to the July 2026 edition of Data Management Digest! As your trusted partner in data innovation, the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...