Reporting

WinEventLog

Jeronimo317
Explorer

Hi team, the issue that I am currently experiencing is that WinEventLog not sending data to the main index . I am new to Splunk and so far have not been able to figure out the reason. Thoughts?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Good!

If your isse was solved, please accept the answer for the other people of the Community.

Ciao and Next Time!

Giuseppe

P.S.: Karma Points are appreciated 😉

View solution in original post

anilchaithu
Builder

@Jeronimo317 

what is your setup? Are you trying to forward wineventlog from remote server to splunk using universal forwarder?

Please make sure you have the following configurations in place

  • open port 9997 on receiving instance
  • configure outputs.conf on UF to send data to splunk indexer
  • open network connection (for port 9997) between remote server & splunk instance

Please refer below page for more details

https://docs.splunk.com/Documentation/Forwarder/8.0.5/Forwarder/HowtoforwarddatatoSplunkEnterprise 

Hope this helps

0 Karma

Jeronimo317
Explorer

Hi @gcusello and @anilchaithu , thank you for your help I figured out the issue. Turned out that the index was not specifically set in the input.conf and by default the ingest was going to main as oppose to wineventlog. Seems to be OK now. Thanks again 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Good!

If your isse was solved, please accept the answer for the other people of the Community.

Ciao and Next Time!

Giuseppe

P.S.: Karma Points are appreciated 😉

Jeronimo317
Explorer

Are you trying to forward wineventlog from remote server to splunk using universal forwarder? - Yes, and it has been working fine. Suddenly I stopped seeing WinEventLog sending data to the main index. What could be a reason and how can I troubleshoot? Thanks

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Jeronimo317,

which Technical Add-On are you using?

See in the inputs.conf if there's an index (usually wineventlog).

Ciao.

Giuseppe

0 Karma

Jeronimo317
Explorer

Hi gcusello, I am not sure what do you mean by which Technical Add-on?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Jeronimo317,

did you created your own inputs.conf or did you take the Splunk_TA_Windows to take the logs from wineventlog?

Index is usually assigned in inputs.conf, so you should see in the active inputs.conf what's the index assignment.

From your answer I suppose that you didn't used the TA but the web gui inputs configuration; if this is your situation, see in the inputs configuration [Settings -- Inputs] what's the index assignment. 

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...