Getting Data In

windows application log files.

alanhowlett
New Member

I'm trying to configure splunk to ingest two application logfiles, not the event logs the actual application logfile (text).

Its my first time ingesting windows forwarder logs (I'm a linux man really), but I did read that it can be done in the inputs.conf so I tried the below:

[monitor://D:\lfbank\wincsl\logs\wincsl-service.log]
disabled = 0
index = wincsl
souurcetype = lfab_wincsl1

[monitor://D:\inetpub\logs\logfiles\W3SVC*]
disabled = 0
index = wincsl
souurcetype = lfab_wincsl2

I do have an outputs.conf configured, but am still seeing no data.

0 Karma

vsai0718
Path Finder

You need to add WindEventLog:Application stanza before monitor.
For Example:

[WinEventLog:Application]
disabled = 0
start_from = oldest
current_only = 0
0 Karma

alanhowlett
New Member

I don't have access to the forwarders. I'm just using the deployment server to send the configs out.

I'm going to have to check things tomorrow with the engineer on site.

As long as my syntax is ok.

0 Karma

briancronrath
Contributor

What does your splunk forwarder logs say, are there any lines including the names of these logs?

0 Karma

alanhowlett
New Member

Corrected the typo drrrrrr. Still not working.

If I look in the GUI I don't see the index, but I have another built and that does show up either. But works.

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

Set your search to All Time, just in case there are timestamping issues. You can also click on the Data Summary which has host, source and sourcetype tabs where you can look at all of the values for each to see if you can see the values you are expecting for any of those metadata fields.

Also, make sure you have no firewalls blocking the traffic. I'm making the assumption that you are already listening on port 9997 on your indexers as well.

0 Karma

alanhowlett
New Member

So is the config above ok ( without the typo).

we are setup for port 9998 using ssl certs signed by the client. And we do have other forwarders that are working ok.

I can see the new indexer now found a config error.

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

Does the wincsl index exist? Also, not sure if this is a typo in your question, or if this is the way your inputs.conf looks, but sourcetype is spelled incorrectly It has two u's.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...