Splunk Search

Failed to find Event Log with channel name

halbeisendv
Path Finder

We needed to retrieve a older evtx file from storage. We placed the file in c:\temp and we created an app to ingest it. Here's the app:

[WinEventLog://Archive-Application-2019-04-04-08-00-56-870]
disabled = 0
current_only = 0
checkpointInterval = 5
index = windows
renderXml=false

We've added the full path to the file name like this:
[WinEventLog://c:\temp\Archive-Application-2019-04-04-08-00-56-870]

We've added the file extension like this:
[WinEventLog://c:\temp\Archive-Application-2019-04-04-08-00-56-870.evtx]

We've deleted fishbucket, we've deleted persistent storage on every splunk restart. Still we get the message, "Failed to find Event Log with channel name=Archive-Application-2019-04-04-08-00-56-870"

We tried splunk add oneshot --that didn't work at all. What do we need to do to ingest this file. Thanks.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Want a chance to win $500 to the Splunk shop? Take our IT Incident Management Survey!

  Top Trends & Best Practices in Incident ManagementSplunk is partnering up with Constellation Research to ...