I am a Splunk newbie needing help. I had successfully setup my Windows PCs to log printing events, specifically event 307. I setup a Splunk report that would list any activity with this event id. I noticed that one PC that shared a printer stopped reporting. I can see on the PC's event log that it is logging print jobs but are not showing up in the Splunk index that collects the logs. Other events from that PC are being logged in the index. I ran some tests on other PCs, doing print jobs "to PDF". It shows up in the index on one other PC but does not for other PCs. I am using the Splunk agent on all my PCs. Is there a way to track an event being logged on a PC and making its way through the splunk agent onto the splunk server and the index? Also, the historic print events that used to show up in the Index no longer do when I choose "All Time" as the time reference.
... View more