Getting Data In

No Wineventlogs With Universal Forwarder 6.1.2 on Windows Server 2008 R2

jodros
Builder

I recently installed the newest UF on a server to test before rolling out to the rest of the environment. I am able to monitor log files on the filesystem, but not wineventlogs. I verified the configuration is correct. Is there a bug with this UF?

Any assistance would be appreciated.

0 Karma
1 Solution

jodros
Builder

I figured it out. There is a statement in the props.conf on the indexers that deletes wineventlog:application data that does not match some regex value. I will need to modify this statement.
Thanks

View solution in original post

jodros
Builder

I figured it out. There is a statement in the props.conf on the indexers that deletes wineventlog:application data that does not match some regex value. I will need to modify this statement.
Thanks

jodros
Builder

@linu1988 thanks for the reply. Will using SOURCE_KEY = MetaData:Host make the REGEX = test123 match on the host sending the log, or will it match on characters within the log itself. I should have clarified that I have used the DEST_KEY = queue and FORMAT = indexQueue successfully in the past.

Thanks

0 Karma

linu1988
Champion

indexQueue is mentioned, so it will be indexed. Refer the document

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Datapipeline

0 Karma

jodros
Builder

I do have another question pertaining to the transforms.conf file. Would the below config route all logs to the normal queue for host test123?

[keep_test123_data]
SOURCE_KEY = MetaData:Host
REGEX = test123
DEST_KEY = queue
FORMAT = indexQueue

0 Karma

jodros
Builder

inputs.conf:
[WinEventLog:Application]
disabled = 0
start_from = oldest
current_only = 0
checkpointInterval = 5
index = techsvcs

As far as I can tell, this is the same wineventlog configuration that I have working on other versions of UF.

There is also an outputs app that is working for 40+ other servers that is applied to this server to indicate how to send data to the indexers.

0 Karma

linu1988
Champion

it works on server 2008 i have tested, could you post your configuration?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...