<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WinEventLog:Security events got reindexed after a disaster recovery event. How do we prevent this reindexing from happening? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-Security-events-got-reindexed-after-a-disaster/m-p/259521#M49817</link>
    <description>&lt;P&gt;For our office Disaster Recovery plan, we use Hyper-V replication to replicate our servers offsite. Yesterday we had a DR event and brought the replicas online. Two of the many servers decided to reindex their WinEventLog:Security events. It was only these two servers and only the WinEventLog:Security events that got reindexed.&lt;/P&gt;

&lt;P&gt;Is there a way to prevent this from happening during a DR event? It pushed us over our licensing cap.&lt;/P&gt;

&lt;P&gt;Thank you in advance,&lt;/P&gt;

&lt;P&gt;Jeremy&lt;/P&gt;</description>
    <pubDate>Fri, 20 May 2016 14:24:21 GMT</pubDate>
    <dc:creator>jwinderDDS</dc:creator>
    <dc:date>2016-05-20T14:24:21Z</dc:date>
    <item>
      <title>WinEventLog:Security events got reindexed after a disaster recovery event. How do we prevent this reindexing from happening?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-Security-events-got-reindexed-after-a-disaster/m-p/259521#M49817</link>
      <description>&lt;P&gt;For our office Disaster Recovery plan, we use Hyper-V replication to replicate our servers offsite. Yesterday we had a DR event and brought the replicas online. Two of the many servers decided to reindex their WinEventLog:Security events. It was only these two servers and only the WinEventLog:Security events that got reindexed.&lt;/P&gt;

&lt;P&gt;Is there a way to prevent this from happening during a DR event? It pushed us over our licensing cap.&lt;/P&gt;

&lt;P&gt;Thank you in advance,&lt;/P&gt;

&lt;P&gt;Jeremy&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2016 14:24:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-Security-events-got-reindexed-after-a-disaster/m-p/259521#M49817</guid>
      <dc:creator>jwinderDDS</dc:creator>
      <dc:date>2016-05-20T14:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:Security events got reindexed after a disaster recovery event. How do we prevent this reindexing from happening?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-Security-events-got-reindexed-after-a-disaster/m-p/259522#M49818</link>
      <description>&lt;P&gt;Forwarders are not aware of the data collected on other forwarders, (For log files, or wineventlogs etc..)&lt;BR /&gt;
so to avoid indexing the same events twice, you can&lt;BR /&gt;
 - disable one input on one of the forwarder&lt;BR /&gt;
 - disable windows internal cloning of events logs between servers, or put them on different wineventlog groups, that you can decide which ones to monitor or not.&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2016 15:23:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-Security-events-got-reindexed-after-a-disaster/m-p/259522#M49818</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2016-05-20T15:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLog:Security events got reindexed after a disaster recovery event. How do we prevent this reindexing from happening?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-Security-events-got-reindexed-after-a-disaster/m-p/259523#M49819</link>
      <description>&lt;P&gt;The replication I'm talking about is like taking a bit-by-bit clone of the drive, any changed done on the primary are replicated to the secondary. The secondary isn't even powered on or realizes it is a different machine when failed over.&lt;/P&gt;

&lt;P&gt;This is also evident by the fact only one source, WinEventLog:Security, was reindexed. Also this is the only time reindexing has happened and we routinely perform testing on our DR plans, which includes failing over machines.&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2016 13:08:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLog-Security-events-got-reindexed-after-a-disaster/m-p/259523#M49819</guid>
      <dc:creator>jwinderDDS</dc:creator>
      <dc:date>2016-05-23T13:08:18Z</dc:date>
    </item>
  </channel>
</rss>

