Hello,
I have a client with a Windows 2008r2 server running a universal forwarder and set to forward Windows Event, Application, and Security logs to a heavy forwarder. From there the client is using SplunkCloud.
In SplunkCloud, I can see the machine connecting, but it doesn't seem to be sending any information.
I can see the following information:
08-23-2016 01:24:27.191 +0000 INFO Metrics - group=per_host_thruput, series="Machine_Name", kbps=0.031723, eps=0.387102, kb=0.983398, ev=12, avg_age=0.916667, max_age=1
host = idx1.client.splunkcloud.com source = /opt/splunk/var/log/splunk/metrics.log sourcetype = splunkd
The client does not believe it is a GPO problem.
I do not have direct access to the machine But I will be asking the client for the input.conf and output.conf files tomorrow.
Can someone point me in the right direction for solving this problem?
Thanks,
HI Guys!
Thanks for you input. It was a stupid simple mistake, my colleague who set the system-up didn't create a "wineventlog" index, and me being a newby didn't know to look for it.
Thanks for your input!
Could it be a timestamp issue? Did you try searching over all-time to see if you see any results. This might sound silly...but It has happened many times.
I think we need to first see inputs.conf and outputs.conf and go from there. Instead of asking the client for specific files, ask for the entire etc directory in the UF in-case we have more questions.