Windows Event Log files (.evtx) monitoring stop working after a while and the Splunk universal forwarder has to be restarted to start data collection again.
Here is the [monitor] stanza configured to monitor the Windows Event Log files (.evtx):
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerActivity.evtx]
disabled = 0
index = WinEvent
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerManagement.evtx]
disabled = 0
index = WinEvent
Universal forwarder will not poll for inputs for window events when specifying the [monitor] if interval is not specified.
i.e.
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerActivity.evtx]
disabled = 0
index = WinEvent
Solution 1: Specify an interval value for the [monitor] stanza:
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerActivity.evtx]
interval = 60
disabled = 0
index = WinEvent
Solution 2: Use [WinEventLog] stanza for Windows Event Log files monitoring:
[WinEventLog://VisualSVNServerActivity]
disabled = 0
index = WinEvent
Refer to Monitor Windows event log data.
Universal forwarder will not poll for inputs for window events when specifying the [monitor] if interval is not specified.
i.e.
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerActivity.evtx]
disabled = 0
index = WinEvent
Solution 1: Specify an interval value for the [monitor] stanza:
[monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerActivity.evtx]
interval = 60
disabled = 0
index = WinEvent
Solution 2: Use [WinEventLog] stanza for Windows Event Log files monitoring:
[WinEventLog://VisualSVNServerActivity]
disabled = 0
index = WinEvent
Refer to Monitor Windows event log data.