Monitoring Splunk

How to get all EventLog after UF was installed?

sunrise
Contributor

I have a question about EventLog monitoring by Universal Forwarder(UF).

I want to set up the EventLog monitoring on following points.

  • Ignore the past EventLog before UF installing.
  • On restarted, UF sends EventLog data during its down to indexer.

I want to monitor all EventLog after UF was installed, but not before.

I think the parameter like "ignoreOlderThan" in file monitoring is very helpful on this point.
But it's impossible to apply to EventLog monitoring according to following URL.

http://splunk-base.splunk.com/answers/51803/wineventlog-ignoreolderthan-2d

A "current_only=0" sends older events to an Indexer than UF was installed.
And "current_only=1" sends events except during UF's down.

How to get all EventLog after UF was installed?

Thank you.

0 Karma
1 Solution

sunrise
Contributor

By changing current_only parameter, UF can monitor all eventlogs including outage and ignore the past EventLog before UF installing.

current_only=1(inital startup)-> change to current_only=0, and UF restarts

Link page below is correct.

Windows event logs – Define the start time for event collection – do not want current_only OR all hi...

View solution in original post

0 Karma

sunrise
Contributor

By changing current_only parameter, UF can monitor all eventlogs including outage and ignore the past EventLog before UF installing.

current_only=1(inital startup)-> change to current_only=0, and UF restarts

Link page below is correct.

Windows event logs – Define the start time for event collection – do not want current_only OR all hi...

0 Karma

sunrise
Contributor

Sorry, the answer is already existed. I'll test it.

Windows event logs – Define the start time for event collection – do not want current_only OR all history - Splunk Community - http://splunk-base.splunk.com/answers/68446/Windows-event-logs-%E2%80%93-Define-the-start-time-for-e...

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...