 
		
		
		
		
		
	
			
		
		
			
					
		Windows Event Log files (.evtx) monitoring stop working after a while and the Splunk universal forwarder has to be restarted to start data collection again.
Here is the [monitor] stanza configured to monitor the Windows Event Log files (.evtx): 
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerActivity.evtx]
disabled = 0
index = WinEvent
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerManagement.evtx]
disabled = 0
index = WinEvent
 
		
		
		
		
		
	
			
		
		
			
					
		Universal forwarder will not poll for inputs for window events when specifying the [monitor] if interval is not specified. 
i.e. 
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerActivity.evtx] 
disabled = 0 
index = WinEvent
Solution 1: Specify an interval value for the [monitor] stanza: 
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerActivity.evtx] 
interval = 60 
disabled = 0 
index = WinEvent
Solution 2: Use [WinEventLog] stanza for Windows Event Log files monitoring: 
[WinEventLog://VisualSVNServerActivity] 
disabled = 0 
index = WinEvent
Refer to Monitor Windows event log data.
 
		
		
		
		
		
	
			
		
		
			
					
		Universal forwarder will not poll for inputs for window events when specifying the [monitor] if interval is not specified. 
i.e. 
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerActivity.evtx] 
disabled = 0 
index = WinEvent
Solution 1: Specify an interval value for the [monitor] stanza: 
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerActivity.evtx] 
interval = 60 
disabled = 0 
index = WinEvent
Solution 2: Use [WinEventLog] stanza for Windows Event Log files monitoring: 
[WinEventLog://VisualSVNServerActivity] 
disabled = 0 
index = WinEvent
Refer to Monitor Windows event log data.
