I'm going to try to explain this problem with a video. Watch as I list the monitors on a windows host and you'll see the file I want to search is listed. After that I open the log file and look at the time of the last event. Then I go over to the splunk web portal and do a search. I even click on the source directly from the summary page and the event is still not listed. You can see the last event in the search results is not what I saw from the real Windows event log. After that, I restart the universal forwarder then go back to the web portal, click the search a couple more times, and it is there. So it only seems to pick up the data after I do a restart of the forwarder...
http://screencast.com/t/ILPGo40B
... View more