Getting Data In

windows application log files.

alanhowlett
New Member

I'm trying to configure splunk to ingest two application logfiles, not the event logs the actual application logfile (text).

Its my first time ingesting windows forwarder logs (I'm a linux man really), but I did read that it can be done in the inputs.conf so I tried the below:

[monitor://D:\lfbank\wincsl\logs\wincsl-service.log]
disabled = 0
index = wincsl
souurcetype = lfab_wincsl1

[monitor://D:\inetpub\logs\logfiles\W3SVC*]
disabled = 0
index = wincsl
souurcetype = lfab_wincsl2

I do have an outputs.conf configured, but am still seeing no data.

0 Karma

vsai0718
Path Finder

You need to add WindEventLog:Application stanza before monitor.
For Example:

[WinEventLog:Application]
disabled = 0
start_from = oldest
current_only = 0
0 Karma

alanhowlett
New Member

I don't have access to the forwarders. I'm just using the deployment server to send the configs out.

I'm going to have to check things tomorrow with the engineer on site.

As long as my syntax is ok.

0 Karma

briancronrath
Contributor

What does your splunk forwarder logs say, are there any lines including the names of these logs?

0 Karma

alanhowlett
New Member

Corrected the typo drrrrrr. Still not working.

If I look in the GUI I don't see the index, but I have another built and that does show up either. But works.

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

Set your search to All Time, just in case there are timestamping issues. You can also click on the Data Summary which has host, source and sourcetype tabs where you can look at all of the values for each to see if you can see the values you are expecting for any of those metadata fields.

Also, make sure you have no firewalls blocking the traffic. I'm making the assumption that you are already listening on port 9997 on your indexers as well.

0 Karma

alanhowlett
New Member

So is the config above ok ( without the typo).

we are setup for port 9998 using ssl certs signed by the client. And we do have other forwarders that are working ok.

I can see the new indexer now found a config error.

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

Does the wincsl index exist? Also, not sure if this is a typo in your question, or if this is the way your inputs.conf looks, but sourcetype is spelled incorrectly It has two u's.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...