Hi,
after a Windows system crash of the raid controller, I only get empty reports. I moved the installation to a VM and everything looked good... But: empty dashboard reports!
Getting data from the windows eventlogs into splunk still works, but most entries have this problem:
Message=Splunk could not get the description for this event. Either the component that raises this event is not installed on your local computer or the installation is corrupt.
FormatMessage error...
I checked wecutil gs and I found, it was set to "rendered text" for both of my subscriptions. I've set it back to "events" but still no luck. Restart of the service: not luck.
I'm running SPLUNK Enterprise 8.2.5 on Windows Server 2016.
Any hints are highly appreciated!
Best, EL