I'm using splunk universal forwarder version 6.1.2 on Windows Servers to index EventLogs. The Events are indexed (indexer version 6.1.2), however the message field contains following message:
Splunk could not get the description for this event. Either the component that raises this event is not installed on your local computer or the installation is corrupt.
In the Event Viewer on the Windows Server the message field is displayed correctly. I couldn't identify a specific EventID nor Server version, it happens on win server 2003 and also 2008r2. However it seems to happen mostly in Security and Application Log.
If found an article that describes the problem, however it addressed a bug in 4.3.x
Any ideas or suggestions? Could it be the same bug?
... View more