Getting Data In

How splunk UF handle windows EventLog rotation?

xiyangyang
Path Finder

We have a file sever which generates about 7G windows Event Log a day. Windows Event Log is rotated as soon as the size reach to 200MB. We want to use splunk UF to get the logs, but we have follow concern:
Is it possible that splunk UF cannot get the log right before the rotation happened ?
(we don't know how UF handle event logs, we just assume UF might not get the one right before the rotation before it is moved to backup so fast)
We only need to know what happen in the general situation but not in the case such like UF service is down or Indexer server is down.)

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

If you use the WinEventLog monitor (https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf#Windows_Event_Log_Monitor) it shouldn't care about the log rolling. It doesn't actually care about the log file itself as it monitors the specific event log channel rather than the .evtx file.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...