Hello Freinds,
Current setup - we have multiple locations in Europe, and each location we have multiple windows servers and those servers' forwarding logs to windows log collector server. from log collector to collect the logs on splunk cloud. few sites we are not receiving logs from windows servers, we checked in the GPO policy and its properly configured. while checking gpresult some of the settings not properly applied. i tried gpupdate and tried again. but issue still to be continued.
If I understand your question correctly - you have several geographically distributed windows server from which you want to send events using WEF to a central collector (or a bunch of collectors) from which you'll be able to pick up the events with a Splunk forwarder.
And while the overal idea is good, some WEF subscriptions don't work.
Well, the problem is - it's a completely not Splunk-related issue. It's a question for your windows team, especially as you say that GPOs are not properly applied. This is something you have to resolve with your AD/Windows admins.
Yes. you are correct. working with windows team, but we are looking for solution in the forum.
If I understand your question correctly - you have several geographically distributed windows server from which you want to send events using WEF to a central collector (or a bunch of collectors) from which you'll be able to pick up the events with a Splunk forwarder.
And while the overal idea is good, some WEF subscriptions don't work.
Well, the problem is - it's a completely not Splunk-related issue. It's a question for your windows team, especially as you say that GPOs are not properly applied. This is something you have to resolve with your AD/Windows admins.