Getting Data In

windows application log files.

alanhowlett
New Member

I'm trying to configure splunk to ingest two application logfiles, not the event logs the actual application logfile (text).

Its my first time ingesting windows forwarder logs (I'm a linux man really), but I did read that it can be done in the inputs.conf so I tried the below:

[monitor://D:\lfbank\wincsl\logs\wincsl-service.log]
disabled = 0
index = wincsl
souurcetype = lfab_wincsl1

[monitor://D:\inetpub\logs\logfiles\W3SVC*]
disabled = 0
index = wincsl
souurcetype = lfab_wincsl2

I do have an outputs.conf configured, but am still seeing no data.

0 Karma

vsai0718
Path Finder

You need to add WindEventLog:Application stanza before monitor.
For Example:

[WinEventLog:Application]
disabled = 0
start_from = oldest
current_only = 0
0 Karma

alanhowlett
New Member

I don't have access to the forwarders. I'm just using the deployment server to send the configs out.

I'm going to have to check things tomorrow with the engineer on site.

As long as my syntax is ok.

0 Karma

briancronrath
Contributor

What does your splunk forwarder logs say, are there any lines including the names of these logs?

0 Karma

alanhowlett
New Member

Corrected the typo drrrrrr. Still not working.

If I look in the GUI I don't see the index, but I have another built and that does show up either. But works.

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

Set your search to All Time, just in case there are timestamping issues. You can also click on the Data Summary which has host, source and sourcetype tabs where you can look at all of the values for each to see if you can see the values you are expecting for any of those metadata fields.

Also, make sure you have no firewalls blocking the traffic. I'm making the assumption that you are already listening on port 9997 on your indexers as well.

0 Karma

alanhowlett
New Member

So is the config above ok ( without the typo).

we are setup for port 9998 using ssl certs signed by the client. And we do have other forwarders that are working ok.

I can see the new indexer now found a config error.

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

Does the wincsl index exist? Also, not sure if this is a typo in your question, or if this is the way your inputs.conf looks, but sourcetype is spelled incorrectly It has two u's.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...