Getting Data In

Windows event logs not sending to splunk log collector

sankardevarajan
Explorer

Hello Freinds,

Current setup - we have multiple locations in Europe, and each location we have multiple windows servers and those servers' forwarding logs to windows log collector server. from log collector to collect the logs on splunk cloud.  few sites we are not receiving logs from windows servers, we checked in the GPO policy and its properly configured. while checking gpresult some of the settings not properly applied. i tried gpupdate and tried again. but issue still to be continued. 

 

0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

If I understand your question correctly - you have several geographically distributed windows server from which you want to send events using WEF to a central collector (or a bunch of collectors) from which you'll be able to pick up the events with a Splunk forwarder.

And while the overal idea is good, some WEF subscriptions don't work.

Well, the problem is - it's a completely not Splunk-related issue. It's a question for your windows team, especially as you say that GPOs are not properly applied. This is something you have to resolve with your AD/Windows admins.

View solution in original post

sankardevarajan
Explorer

Yes. you are correct. working with windows team, but we are looking for solution in the forum.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

If I understand your question correctly - you have several geographically distributed windows server from which you want to send events using WEF to a central collector (or a bunch of collectors) from which you'll be able to pick up the events with a Splunk forwarder.

And while the overal idea is good, some WEF subscriptions don't work.

Well, the problem is - it's a completely not Splunk-related issue. It's a question for your windows team, especially as you say that GPOs are not properly applied. This is something you have to resolve with your AD/Windows admins.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...