Security

Do not receive Windows Event Logs but Perfmon logs from Domain Controller

jan_wohlers
Path Finder

Hey everyone,

it's me again. Today I have the problem, that I only get perfmon logs from 2 Domain controllers. We use a deployment server and all other dcs are forwarding all events except these 2. Do you have any Idea why these DCs only forwarding perfmon logs but no windows security eventlogs?

I don't think that this is a firewall problem because perfmon logs are coming in.

Thanks for any reply.

/Jan

Tags (2)
0 Karma

MarioM
Motivator

I would check locally to see if you can view any new events from eventviewer itself and if the case i would check the splunkforwarder\var\log\splunk\splunkd.log for any errors...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...