Getting Data In

How splunk UF handle windows EventLog rotation?

xiyangyang
Path Finder

We have a file sever which generates about 7G windows Event Log a day. Windows Event Log is rotated as soon as the size reach to 200MB. We want to use splunk UF to get the logs, but we have follow concern:
Is it possible that splunk UF cannot get the log right before the rotation happened ?
(we don't know how UF handle event logs, we just assume UF might not get the one right before the rotation before it is moved to backup so fast)
We only need to know what happen in the general situation but not in the case such like UF service is down or Indexer server is down.)

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

If you use the WinEventLog monitor (https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf#Windows_Event_Log_Monitor) it shouldn't care about the log rolling. It doesn't actually care about the log file itself as it monitors the specific event log channel rather than the .evtx file.

0 Karma
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...