Getting Data In

Persistent queues for Windows event logs

reginaldsheetz_
New Member

Where does Splunk store the persistent queues for Windows logs. I am able to find the TCP and UDP queued logs but cannot find the Windows logs.

0 Karma
1 Solution

alemarzu
Motivator

Hello there @reginaldsheetz_mantech

The path for PQs > $SPLUNK_HOME/var/run/splunk/[tcpin|udpin]/pq__<port>

https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Usepersistentqueues#Persistent_queue_l...

View solution in original post

0 Karma

alemarzu
Motivator

Hello there @reginaldsheetz_mantech

The path for PQs > $SPLUNK_HOME/var/run/splunk/[tcpin|udpin]/pq__<port>

https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Usepersistentqueues#Persistent_queue_l...

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...