Getting Data In

Splunk Universal Forwarder not forwarding Windows Event Log : Application

jyotishman22
New Member

I am using the universal forwarder to forward Windows event logs - Security, System and Application. The security and system are forwarded just fine but the Application logs are not being forwarded. The corresponding log entry in the splunkd file says:
"Finished processing existing Windows Event Log 'Application': total_events='0' with empty_msg='0'."

Could you please suggest how I should go about debugging this issue?

Tags (1)
0 Karma

jyotishman22
New Member

I cleared the event log files and restarted Splunk and that did the trick, I have been receiving the logs since then. Thanks!

0 Karma

mship
Path Finder

Couple of basic questions...

Did you check to see if the application event log on the local machine has any data?

Did you move/create new indexes?

mship
Path Finder

The outputs.conf file is unique to forwarders and it defines how forwarders send data to receivers. Check that to make sure that it is configure properly...must do this through the CLI. You can also enable the deployment monitor app to further trouble shoot while we try to figure this out. http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Startthedeploymentmonitor

0 Karma

jyotishman22
New Member

I haven't modified the outputs.conf file, if I save the event viewer items to a local file and ask splunk to monitor the local file I get the same message on the splunkd log:

06-05-2012 13:43:40.103 -0400 INFO WinEventLogInputProcessor - main-thread: Finished processing existing Windows Event Log 'C:\Program Files (x86)\EBSCO\SDIAlertService\Logs\temp.evtx': total_events='0' with empty_msg='0'.

However this file is about 12MB in size and contains about 200 events. I installed the UF through the GUI.

0 Karma

mship
Path Finder

What does outputs.conf on the UF read?

0 Karma

jyotishman22
New Member

I am now monitoring the Windows event log directory, the corresponding entry on my inputs.conf file says:

[monitor://C:WindowsSystem32WinevtLogsApplication.evtx]
disabled = false

I can view the entries through the Event Viewer. However these aren't being forwarded by the forwarder, the splunkd log file entry shows:

06-05-2012 13:21:05.665 -0400 INFO WinEventLogInputProcessor - main-thread: Finished processing existing Windows Event Log 'C:WindowsSystem32WinevtLogsApplication.evtx': total_events='0' with empty_msg='0'.

Any suggestions/work arounds would be appreciated.

0 Karma

jyotishman22
New Member

Yes, the application event log has data which I can view through the Event Viewer. The machine is running Windows 2008, I was reading about the alwaysOpenFile option ... would this be applicable in this case?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...