I pulled this from the splunkd log. I finally have my Windows 2016 box checking into Splunk. I can see it in Forwarder Management however it is not pulling the Windows Event logs for Application and Security.
Here's my inputs.conf:
[default]
host = ctw-ansible0101
[WinEventLog://Application]
disabled = 0
index = heats-test
[WinEventLog://Security]
disabled = 0
index = heats-test
[monitor://$SPLUNK_HOME\var\log\splunk\splunkd.log]
index = heats-test
04-25-2017 11:26:49.240 -0400 WARN IndexerService - Received event for unconfigured/disabled/deleted index=heats-test with source="source::C:\Program Files\Splunk\var\log\splunk\splunkd.log" host="host::ctw-ansible0101" sourcetype="sourcetype::splunkd". So far received events from 1 missing index(es).
This index is in Splunk so I'm not sure why it says it's unconfigured/disabled/deleted. Any ideas?
Search for the event log you are looking for in the search text box.
For eg:- if you want to search an event log with the name "TEST" search for-
TEST source="WinEventLog:Application"
in the Splunk search text box
Still no joy or logs coming in. No longer seeing any errors about indexes just not receiving the logs. I put an event into the Application log - can't find it in Splunk still.
Hello heats,
looks like your index is not configured correctly,
will recommend to use underscore and not hyphen for indexes names (and in splunk in general)
also check out this document for troubleshooting:
http://docs.splunk.com/Documentation/Splunk/6.5.3/Troubleshooting/Cantfinddata
Created new heats_test index and made the changes in inputs.conf. Made a new event in the application log and restarted the splunk service. Still no joy - no logs coming in to the heats_test index. The good news is I don't see that error anymore in the splunkd log.
If you have a distributed Splunk system, make sure the heats-test index is defined on all indexers, not just the search head.
We only have one indexer.