All Apps and Add-ons

Is there any configuration tricks concerning getting Windows Print Jobs into splunk?

scottrunyon
Contributor

We all know that Windows reporting and event logging are a complete mess, so this might not be a Splunk issue but I have to ask.

I have set up inputs.config to ingest Windows print jobs on a UF -
[WinPrintMon://jobs]
type=job
index=winprintmon

I am getting multiple copies of some events and only part of some events and missing some entirely. I noticed that the interval defaults to 60 seconds. There is a "special value" of 0, that forces this scripted input to be run continuously, If I would set the interval to 0, would this help? Or maybe making the interval longer, say interval=300, would decrease the duplicates?

As always, any help would be greatly appreciated so I can stopping pestering my Server Admin 🙂

Scott

0 Karma
1 Solution

Azeemering
Builder

I would actually increase the interval (600) and test what happens with that. Print servers are generally not too busy....
Also add baseline=0

View solution in original post

0 Karma

Azeemering
Builder

I would actually increase the interval (600) and test what happens with that. Print servers are generally not too busy....
Also add baseline=0

0 Karma

scottrunyon
Contributor

I am adding those to the config. Hopefully it works.

Scott

0 Karma

scottrunyon
Contributor

These changes didn't help.

I spoke with the system admin and after looking at the logs, he is opening a ticket with Microsoft.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...