ok... so far i have no luck.
Filesystem Permissions are ok
Domain Permissions are ok
Virusscanner disabled on plunk server & target machine -> no results
index=_internal source="*splunkd.log" wmi -> only 2 info entries since yesterday
12/21/10 4:12:01.588 PM
12-21-2010 16:12:01.588 INFO IndexProcessor - rtsearch connection terminated, filter = '[ AND index::main wmi ]', _actionStreams = 0
12/21/10 4:10:40.885 PM
12-21-2010 16:10:40.885 INFO IndexProcessor - rtsearch connection established, filter = '[ AND index::main wmi ]', _activeStreams = 1, queue_size = 10000, blocking = FALSE
It's like there isn't even an attempt to read the eventlogs from the remote machine.
... View more