My colleague has setup a Windows Printer App following the below link http://docs.splunk.com/Documentation/Splunk/7.0.3/Data/MonitorWindowsprinterinformation
However, I am not too sure where the print events are being pulled from as after checking the Event Viewer (Windows > PrintService) some logs are empty or do not contain any printing logs so I am at a loss in understanding where they are pulled from. Does anyone know on a more low level detail how Splunk forwards these events?
Splunk WinPrintMon input calls an exe file called splunk-winprintmon.exe to get those inputs.Ensure that Print service is enabled in the server to get those data.
splunk-winprintmon.exe (available with UF) collects driver,ports and jobs details. It might not from events viewer.
Thank you for this but how do I check if the service is enabled ?
The actual issue is that when the user prints multiple pages it only shows 1 page being printed on both WinEvent logs as well as in splunk.