Security

Do not receive Windows Event Logs but Perfmon logs from Domain Controller

jan_wohlers
Path Finder

Hey everyone,

it's me again. Today I have the problem, that I only get perfmon logs from 2 Domain controllers. We use a deployment server and all other dcs are forwarding all events except these 2. Do you have any Idea why these DCs only forwarding perfmon logs but no windows security eventlogs?

I don't think that this is a firewall problem because perfmon logs are coming in.

Thanks for any reply.

/Jan

Tags (2)
0 Karma

MarioM
Motivator

I would check locally to see if you can view any new events from eventviewer itself and if the case i would check the splunkforwarder\var\log\splunk\splunkd.log for any errors...

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...