We all know that Windows reporting and event logging are a complete mess, so this might not be a Splunk issue but I have to ask.
I have set up inputs.config to ingest Windows print jobs on a UF -
[WinPrintMon://jobs]
type=job
index=winprintmon
I am getting multiple copies of some events and only part of some events and missing some entirely. I noticed that the interval defaults to 60 seconds. There is a "special value" of 0, that forces this scripted input to be run continuously, If I would set the interval to 0, would this help? Or maybe making the interval longer, say interval=300, would decrease the duplicates?
As always, any help would be greatly appreciated so I can stopping pestering my Server Admin 🙂
Scott
I would actually increase the interval (600) and test what happens with that. Print servers are generally not too busy....
Also add baseline=0
I would actually increase the interval (600) and test what happens with that. Print servers are generally not too busy....
Also add baseline=0
I am adding those to the config. Hopefully it works.
Scott
These changes didn't help.
I spoke with the system admin and after looking at the logs, he is opening a ticket with Microsoft.