Getting Data In
Highlighted

Persistent queues for Windows event logs

New Member

Where does Splunk store the persistent queues for Windows logs. I am able to find the TCP and UDP queued logs but cannot find the Windows logs.

0 Karma
Highlighted

Re: Persistent queues for Windows event logs

Motivator

Hello there @reginaldsheetz_mantech

The path for PQs > $SPLUNK_HOME/var/run/splunk/[tcpin|udpin]/pq__<port>

https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Usepersistentqueues#Persistent_queue_l...

View solution in original post

0 Karma