We are facing a similar issue as well. We are trying to read windows event logs from a machine which has a Splunk forwarder installed version 5.0.1. The inputs.conf file is as below:
[WinEventLog://Application]
checkpointInterval = 5
current_only = 0
disabled = 0
index = mag_nprod
start_from = oldest
[WinEventLog://System]
checkpointInterval = 5
current_only = 0
disabled = 0
index = mag_nprod
start_from = oldest
The following error message is present in the Splunkd logs:
10-09-2014 15:47:22.660 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
10-09-2014 15:47:22.660 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
10-09-2014 15:47:19.034 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
10-09-2014 15:47:18.409 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
10-09-2014 15:46:51.783 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
10-09-2014 15:46:27.158 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
Any suggestions please?
... View more