<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Missing Windows Event Logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Missing-Windows-Event-Logs/m-p/107917#M22682</link>
    <description>&lt;P&gt;Can you describe the input you've got configured? Are you writing event logs to a file, or polling via WMI?&lt;/P&gt;</description>
    <pubDate>Tue, 03 Apr 2012 16:51:15 GMT</pubDate>
    <dc:creator>jbsplunk</dc:creator>
    <dc:date>2012-04-03T16:51:15Z</dc:date>
    <item>
      <title>Missing Windows Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-Windows-Event-Logs/m-p/107916#M22681</link>
      <description>&lt;P&gt;Since the Windows Event Viewer archives and generates a new log at 20MB (its maximum capacity), is there a risk that the Windows monitor would fail to consume an event if the events are being generated at a very quick pace? In other words, the creation of windows event logs is outpacing the Splunk monitor.  For example, say your Windows server is generated X kb of Windows Security Events per second, but the splunk monitor can only consume X - 1 kb events per second, by the time the log hits 20MB and is archived, the splunk monitor has failed to consume all 20MB, so in theory I am missing some events.  Is this a possibility?   &lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2012 15:18:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-Windows-Event-Logs/m-p/107916#M22681</guid>
      <dc:creator>carmackd</dc:creator>
      <dc:date>2012-04-03T15:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Missing Windows Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-Windows-Event-Logs/m-p/107917#M22682</link>
      <description>&lt;P&gt;Can you describe the input you've got configured? Are you writing event logs to a file, or polling via WMI?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2012 16:51:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-Windows-Event-Logs/m-p/107917#M22682</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2012-04-03T16:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: Missing Windows Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-Windows-Event-Logs/m-p/107918#M22683</link>
      <description>&lt;P&gt;This does not directly address your question, but if this does become an issue, you may be able to switch from archiving events, to 'overwrite events older than X days' and increasing the log size so it has time to pull. Although, I don't think you'll have that issue, I just don't have any proof to support it. &lt;BR /&gt;
Just a suggestion though.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2012 21:06:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-Windows-Event-Logs/m-p/107918#M22683</guid>
      <dc:creator>jsb22</dc:creator>
      <dc:date>2012-04-03T21:06:45Z</dc:date>
    </item>
  </channel>
</rss>

