<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How splunk UF handle windows EventLog rotation? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-splunk-UF-handle-windows-EventLog-rotation/m-p/445672#M77540</link>
    <description>&lt;P&gt;We have a file sever which generates about 7G windows Event Log a day. Windows Event Log is rotated as soon as the size reach to 200MB. We want to use splunk UF to get the logs, but we have follow concern:&lt;BR /&gt;
&lt;STRONG&gt;Is it possible that splunk UF cannot get the log right before the rotation happened ?&lt;/STRONG&gt;&lt;BR /&gt;
(we don't know how UF handle event logs, we just assume UF might not get the one right before the rotation before it is moved to backup so fast)&lt;BR /&gt;
We only need to know what happen in the general situation but not in the case such like UF service is down or Indexer server is down.)&lt;/P&gt;</description>
    <pubDate>Mon, 01 Jul 2019 00:44:31 GMT</pubDate>
    <dc:creator>xiyangyang</dc:creator>
    <dc:date>2019-07-01T00:44:31Z</dc:date>
    <item>
      <title>How splunk UF handle windows EventLog rotation?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-splunk-UF-handle-windows-EventLog-rotation/m-p/445672#M77540</link>
      <description>&lt;P&gt;We have a file sever which generates about 7G windows Event Log a day. Windows Event Log is rotated as soon as the size reach to 200MB. We want to use splunk UF to get the logs, but we have follow concern:&lt;BR /&gt;
&lt;STRONG&gt;Is it possible that splunk UF cannot get the log right before the rotation happened ?&lt;/STRONG&gt;&lt;BR /&gt;
(we don't know how UF handle event logs, we just assume UF might not get the one right before the rotation before it is moved to backup so fast)&lt;BR /&gt;
We only need to know what happen in the general situation but not in the case such like UF service is down or Indexer server is down.)&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 00:44:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-splunk-UF-handle-windows-EventLog-rotation/m-p/445672#M77540</guid>
      <dc:creator>xiyangyang</dc:creator>
      <dc:date>2019-07-01T00:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: How splunk UF handle windows EventLog rotation?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-splunk-UF-handle-windows-EventLog-rotation/m-p/445673#M77541</link>
      <description>&lt;P&gt;If you use the WinEventLog monitor (&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf#Windows_Event_Log_Monitor"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf#Windows_Event_Log_Monitor&lt;/A&gt;) it shouldn't care about the log rolling. It doesn't actually care about the log file itself as it monitors the specific event log channel rather than the .evtx file.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 16:54:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-splunk-UF-handle-windows-EventLog-rotation/m-p/445673#M77541</guid>
      <dc:creator>mdsnmss</dc:creator>
      <dc:date>2019-07-01T16:54:26Z</dc:date>
    </item>
  </channel>
</rss>

