Hello
I upgraded to a 6.3.1 Splunk forwarder on a Windows 2012 server. Connectivity is fine and Security logs are coming through, but I can't see Application or System logs (I ensured all three boxes had been checked during the installation process) - I checked 'system>local>inputs.conf' and added the stanzas detailed on this site [WinEventLog://Application] , etc, but no joy .
The previous version was 6.1.2 and all logs were coming through. I uninstalled the new version and put this back on - all logs were seen (I didn't need to change the inputs.conf file either) .
Have checked splunkd.log after restarting the service, but I can't see a message that details what I am doing wrong - all help appreciated!
btw, the Splunk Indexer and the web server are running OEL6, if this has any bearing. They are working correctly .
... View more