Monitoring Splunk

Splunk Universal Forwarder not monitoring WindowEvent Security logs suddenly

shivakarnati
New Member

The Splunk Universal forwarder is stopped forwarding windows Event Security logs,
After check the system logs we came to know that the system time has changed and at that point of time the Splunk UF is not stopped the forwarding. Please help me how to troubleshoot and I have done the following.

1) I restarted the Splunk Universal Forwarder
2) I deleted inputs.conf file and again added that file.

Tags (1)
0 Karma

shivakarnati
New Member

The Splunk Universal forwarder is stopped forwarding windows Event Security logs,
After check the system logs we came to know that the system time has changed and at that point of time the Splunk UF is stopped the forwarding. Please help me how to troubleshoot and I have done the following.
1) I restarted the Splunk Universal Forwarder
2) I deleted inputs.conf file and again added that file.

0 Karma

p_gurav
Champion

Please check _internal index for any error.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...