Running ESM 9.6 all in one. No events from any Windows data sources show in dashboard. I see the data come in /var/log/data/inline/thirdparty.logs/##/in/data* and then go away but nothing in the dashboard.
Events from Linux Syslog come in and show up in the dashboard no problem.
Restriction of Historical Event Inserts Under ESM Properties -> Database -> Database Settings (Sorry if this is incorrect, I do not have access to a 9.6 device, however one of the settings under there should have it)
If it is set to restrict historical inserts, the data will come to the receiver, get parsed, go to the receiver DB and the ESM will not pull it.
If this is not set, then you may be receiving historical data and need to change your time frame based on the events coming in (possibly just set to all time to see)
Lastly, depending on how you are collecting windows data, it may potentially be a misformatting of data for the WMI parser. Are you collecting via credentialed pull request from WinRM, or are you using a third party agent to push the data?
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.