Monitoring Splunk

Windows Defender logs

seanmartin
Observer

Hi, I know as part of SPL-212687 this issue was fixed in 8.2.7 and 9.0+ however we have had some hosts drop their defender logs after receiving a Windows Defender update. These UFs are on version 9.0.2 but have still reported this issue.

Is there any known problem that would cause this?

Labels (1)
0 Karma

seanmartin
Observer

We have had a second instance of this happening overnight.

Last nights update is 4.18.24020.7

The previous update that caused this issue was 4.18.23110.3

 

Both are showing up in event viewer as event ID: 2014

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...