Getting Data In

windows application log files.

alanhowlett
New Member

I'm trying to configure splunk to ingest two application logfiles, not the event logs the actual application logfile (text).

Its my first time ingesting windows forwarder logs (I'm a linux man really), but I did read that it can be done in the inputs.conf so I tried the below:

[monitor://D:\lfbank\wincsl\logs\wincsl-service.log]
disabled = 0
index = wincsl
souurcetype = lfab_wincsl1

[monitor://D:\inetpub\logs\logfiles\W3SVC*]
disabled = 0
index = wincsl
souurcetype = lfab_wincsl2

I do have an outputs.conf configured, but am still seeing no data.

0 Karma

vsai0718
Path Finder

You need to add WindEventLog:Application stanza before monitor.
For Example:

[WinEventLog:Application]
disabled = 0
start_from = oldest
current_only = 0
0 Karma

alanhowlett
New Member

I don't have access to the forwarders. I'm just using the deployment server to send the configs out.

I'm going to have to check things tomorrow with the engineer on site.

As long as my syntax is ok.

0 Karma

briancronrath
Contributor

What does your splunk forwarder logs say, are there any lines including the names of these logs?

0 Karma

alanhowlett
New Member

Corrected the typo drrrrrr. Still not working.

If I look in the GUI I don't see the index, but I have another built and that does show up either. But works.

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

Set your search to All Time, just in case there are timestamping issues. You can also click on the Data Summary which has host, source and sourcetype tabs where you can look at all of the values for each to see if you can see the values you are expecting for any of those metadata fields.

Also, make sure you have no firewalls blocking the traffic. I'm making the assumption that you are already listening on port 9997 on your indexers as well.

0 Karma

alanhowlett
New Member

So is the config above ok ( without the typo).

we are setup for port 9998 using ssl certs signed by the client. And we do have other forwarders that are working ok.

I can see the new indexer now found a config error.

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

Does the wincsl index exist? Also, not sure if this is a typo in your question, or if this is the way your inputs.conf looks, but sourcetype is spelled incorrectly It has two u's.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...