<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Event Logs and Splunk-Can Splunk be configured to delete event logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Logs-and-Splunk-Can-Splunk-be-configured-to-delete/m-p/89987#M18668</link>
    <description>&lt;P&gt;is there any implications that could happen if it were set to overwrite and current_only set to 1?&lt;/P&gt;</description>
    <pubDate>Wed, 07 May 2014 16:05:34 GMT</pubDate>
    <dc:creator>aelliott</dc:creator>
    <dc:date>2014-05-07T16:05:34Z</dc:date>
    <item>
      <title>Windows Event Logs and Splunk-Can Splunk be configured to delete event logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Logs-and-Splunk-Can-Splunk-be-configured-to-delete/m-p/89984#M18665</link>
      <description>&lt;P&gt;Is there any capability within Splunk so it automatically deletes the Application, Security, and System Logs in Event Viewer after Splunk receives the events?  We currently have Windows Server 2003 R2 but also looking to implement Windows Server 2008 R2.  Specifically, I'm curious as to if there are any configuration options available in Splunk to delete the logs in Event Viewer after Splunk gets the data from these logs.  We're looking for an alternative to creating a Group Policy Object that will overwrite the logs.  Thanks in advance to anyone willing to provide input&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2011 20:58:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Logs-and-Splunk-Can-Splunk-be-configured-to-delete/m-p/89984#M18665</guid>
      <dc:creator>sysadmin74</dc:creator>
      <dc:date>2011-10-11T20:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Logs and Splunk-Can Splunk be configured to delete event logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Logs-and-Splunk-Can-Splunk-be-configured-to-delete/m-p/89985#M18666</link>
      <description>&lt;P&gt;No, not built in.  &lt;/P&gt;

&lt;P&gt;Your best bet is a Group Policy that sets the server logs to Overwrite as needed.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2011 21:20:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Logs-and-Splunk-Can-Splunk-be-configured-to-delete/m-p/89985#M18666</guid>
      <dc:creator>kdenton</dc:creator>
      <dc:date>2011-10-11T21:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Logs and Splunk-Can Splunk be configured to delete event logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Logs-and-Splunk-Can-Splunk-be-configured-to-delete/m-p/89986#M18667</link>
      <description>&lt;P&gt;In addition to the previous answer that is completely right, is there a specific reason for you to want to delete or overwrite logs? By default Windows is configured to throw old events FIFO style when the log grows to a certain size (I believe 16MB is the default, or at least used to be). You could lower this limit substantially if you're running a Universal Forwarder on the host since the forwarder will be picking up events immediately as they arrive anyway. That way the logs will be overwritten pretty soon in order to make room for new logs arriving in the event log.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2011 21:44:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Logs-and-Splunk-Can-Splunk-be-configured-to-delete/m-p/89986#M18667</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-10-11T21:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Logs and Splunk-Can Splunk be configured to delete event logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Logs-and-Splunk-Can-Splunk-be-configured-to-delete/m-p/89987#M18668</link>
      <description>&lt;P&gt;is there any implications that could happen if it were set to overwrite and current_only set to 1?&lt;/P&gt;</description>
      <pubDate>Wed, 07 May 2014 16:05:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Logs-and-Splunk-Can-Splunk-be-configured-to-delete/m-p/89987#M18668</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2014-05-07T16:05:34Z</dc:date>
    </item>
  </channel>
</rss>

