Getting Data In

Why is splunkd log not pulling the Windows event logs for application and security?

heats
Explorer

I pulled this from the splunkd log. I finally have my Windows 2016 box checking into Splunk. I can see it in Forwarder Management however it is not pulling the Windows Event logs for Application and Security.

Here's my inputs.conf:

[default]
host = ctw-ansible0101

[WinEventLog://Application]
disabled = 0
index = heats-test
[WinEventLog://Security]
disabled = 0
index = heats-test

[monitor://$SPLUNK_HOME\var\log\splunk\splunkd.log]
index = heats-test

04-25-2017 11:26:49.240 -0400 WARN IndexerService - Received event for unconfigured/disabled/deleted index=heats-test with source="source::C:\Program Files\Splunk\var\log\splunk\splunkd.log" host="host::ctw-ansible0101" sourcetype="sourcetype::splunkd". So far received events from 1 missing index(es).

This index is in Splunk so I'm not sure why it says it's unconfigured/disabled/deleted. Any ideas?

Labels (2)
0 Karma

harsaheb123
Observer

Search for the event log you are looking for in the search text box.

For eg:- if you want to search an event log with the name "TEST" search for-

TEST source="WinEventLog:Application"

in the Splunk search text box

0 Karma

heats
Explorer

Still no joy or logs coming in. No longer seeing any errors about indexes just not receiving the logs. I put an event into the Application log - can't find it in Splunk still.

0 Karma

adonio
Ultra Champion

Hello heats,
looks like your index is not configured correctly,
will recommend to use underscore and not hyphen for indexes names (and in splunk in general)
also check out this document for troubleshooting:
http://docs.splunk.com/Documentation/Splunk/6.5.3/Troubleshooting/Cantfinddata

0 Karma

heats
Explorer

Created new heats_test index and made the changes in inputs.conf. Made a new event in the application log and restarted the splunk service. Still no joy - no logs coming in to the heats_test index. The good news is I don't see that error anymore in the splunkd log.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you have a distributed Splunk system, make sure the heats-test index is defined on all indexers, not just the search head.

---
If this reply helps you, Karma would be appreciated.
0 Karma

heats
Explorer

We only have one indexer.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...