Hi team, the issue that I am currently experiencing is that WinEventLog not sending data to the main index . I am new to Splunk and so far have not been able to figure out the reason. Thoughts?
Good!
If your isse was solved, please accept the answer for the other people of the Community.
Ciao and Next Time!
Giuseppe
P.S.: Karma Points are appreciated 😉
what is your setup? Are you trying to forward wineventlog from remote server to splunk using universal forwarder?
Please make sure you have the following configurations in place
Please refer below page for more details
https://docs.splunk.com/Documentation/Forwarder/8.0.5/Forwarder/HowtoforwarddatatoSplunkEnterprise
Hope this helps
Hi @gcusello and @anilchaithu , thank you for your help I figured out the issue. Turned out that the index was not specifically set in the input.conf and by default the ingest was going to main as oppose to wineventlog. Seems to be OK now. Thanks again
Good!
If your isse was solved, please accept the answer for the other people of the Community.
Ciao and Next Time!
Giuseppe
P.S.: Karma Points are appreciated 😉
Are you trying to forward wineventlog from remote server to splunk using universal forwarder? - Yes, and it has been working fine. Suddenly I stopped seeing WinEventLog sending data to the main index. What could be a reason and how can I troubleshoot? Thanks
Hi @Jeronimo317,
which Technical Add-On are you using?
See in the inputs.conf if there's an index (usually wineventlog).
Ciao.
Giuseppe
Hi gcusello, I am not sure what do you mean by which Technical Add-on?
Hi @Jeronimo317,
did you created your own inputs.conf or did you take the Splunk_TA_Windows to take the logs from wineventlog?
Index is usually assigned in inputs.conf, so you should see in the active inputs.conf what's the index assignment.
From your answer I suppose that you didn't used the TA but the web gui inputs configuration; if this is your situation, see in the inputs configuration [Settings -- Inputs] what's the index assignment.
Ciao.
Giuseppe