Getting Data In

Splunk stopped collectiing Windows Event logs of Remote

quipment
New Member

Hi,

We have Windows 2008 R2 SP1 with splunk 5 installed in Domain network.

We have configured to collect windows "System" event log .

But it suddenly stops collecting windows events when the remote system rebooted. and we cannt get events until the "splunkd" service restarted from the server.

After restarting "splunkd" the server starts get collectiong events. but again stops as soon as the remote server or client rebooted.

The firewall is turned off at both ends.

Thanks ,
Prakash

Tags (1)
0 Karma

quipment
New Member

Hi,

Enabled debug logging level for wmi from link and found out wmi will retry after 5000 seconds Ref : http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/TroubleshootingWMI#Splunk_can.27t... .
alt text

and by editiing wmi.conf from C:\Program Files\Splunk\etc\system\local and setting time out values

Thanks
Prakash

0 Karma

yannK
Splunk Employee
Splunk Employee

make sure that you configured splunk service to start at boot .....

0 Karma

sdaniels
Splunk Employee
Splunk Employee

It may be helpful to share any errors that you are seeing in the splunkd logs.

http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/WhatSplunklogsaboutitself

I would recommend using the Splunk on Splunk App in the future which will help you search across all Splunk logs when you have an issue like this.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...