I attempted to disable the logging with $SPLUNK_HOME/var/log/splunk but it did not change anything.
I currently have problems with 2 x Windows 2008 with UAC enabled. Other Windows 2003 and 2008 WITHOUT UAC are fine. This leads me to believe it is the problem of the forwarder itself. I also tried to install forwarder with administrator rights. Unfortunately nothing has helped so far.
I tried Universal Forwarder 6.2.2, 6.2.4, and the server is 6.2.2.
Does anyone have similar issue?
... View more