Splunk Enterprise

Why am I not seeing Application and Service logs?

tmontney
Builder

I've followed the suggestions on this site but they didn't work.

Went to C:\Program Files\Splunk\etc\system\local and edited inputs.conf.

[WinEventLog://Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational]
disabled = 0
start_from = oldest
current_only = 0

Restarted Splunk (splunkd). Tried to add a computer, but still did not see this listed.

0 Karma

jterry
Splunk Employee
Splunk Employee

can you please add some specifics w/regards to where splunk is running and where the data that you're trying to index is?

0 Karma

jaxjohnny2000
Builder

I can, with the same issue
this is in a separate TA on a Windows Universal Forwarder. This log is not coming in.

[WinEventLog://Microsoft-Windows-TerminalServices-LocalSessionManager/Operational]

disabled = 0
index = eventlog_other
renderXml = false
start_from = oldest

From Btool:

C:\Program Files\SplunkUniversalForwarder\etc\apps\sft_win_eventlogs\local\inputs.conf [WinEventLog://Microsoft-Windows-TerminalServices-LocalSessionManager/Operational]
C:\Program Files\SplunkUniversalForwarder\etc\apps\sft_win_eventlogs\local\inputs.conf disabled = 0
C:\Program Files\SplunkUniversalForwarder\etc\apps\sft_win_eventlogs\local\inputs.conf renderXml = false
C:\Program Files\SplunkUniversalForwarder\etc\apps\sft_win_eventlogs\local\inputs.conf start_from = oldest
C:\Program Files\SplunkUniversalForwarder\etc\apps\sft_win_eventlogs\local\inputs.conf index = win_eventlog_other

0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

 Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research Team (STRT) and ...

Splunk ITSI & Correlated Network Visibility

 Take Your Network Visibility to the Next LevelIn today’s complex IT environments, performance issues can stem ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 3)

Welcome back to Splunk Classroom Chronicles, our ongoing blog series that pulls back the curtain on Splunk ...