We have Splunk Forwarders installed on a lot of 2008 servers, and they all work fine.
The ones installed on 2012 servers however, does not. They send the event logs, but they do not send all the data to the Splunk server. All the 2012 events are there and indexed, but they lack any usable details :(
Any ideas?
↧