Deployment Architecture

Universal forwarder connecting to heavy forwarder but not sending windows event logs

jgorman_THG
Explorer

Hello,

I have a client with a Windows 2008r2 server running a universal forwarder and set to forward Windows Event, Application, and Security logs to a heavy forwarder. From there the client is using SplunkCloud.

In SplunkCloud, I can see the machine connecting, but it doesn't seem to be sending any information.

I can see the following information:

08-23-2016 01:24:27.191 +0000 INFO Metrics - group=per_host_thruput, series="Machine_Name", kbps=0.031723, eps=0.387102, kb=0.983398, ev=12, avg_age=0.916667, max_age=1
host = idx1.client.splunkcloud.com source = /opt/splunk/var/log/splunk/metrics.log sourcetype = splunkd

The client does not believe it is a GPO problem.

I do not have direct access to the machine But I will be asking the client for the input.conf and output.conf files tomorrow.

Can someone point me in the right direction for solving this problem?

Thanks,

0 Karma

jgorman_THG
Explorer

HI Guys!

Thanks for you input. It was a stupid simple mistake, my colleague who set the system-up didn't create a "wineventlog" index, and me being a newby didn't know to look for it.

Thanks for your input!

0 Karma

sk314
Builder

Could it be a timestamp issue? Did you try searching over all-time to see if you see any results. This might sound silly...but It has happened many times.

0 Karma

rharrisssi
Path Finder

I think we need to first see inputs.conf and outputs.conf and go from there. Instead of asking the client for specific files, ask for the entire etc directory in the UF in-case we have more questions.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...