Monitoring Splunk

Windows Defender logs

seanmartin
Observer

Hi, I know as part of SPL-212687 this issue was fixed in 8.2.7 and 9.0+ however we have had some hosts drop their defender logs after receiving a Windows Defender update. These UFs are on version 9.0.2 but have still reported this issue.

Is there any known problem that would cause this?

Labels (1)
0 Karma

seanmartin
Observer

We have had a second instance of this happening overnight.

Last nights update is 4.18.24020.7

The previous update that caused this issue was 4.18.23110.3

 

Both are showing up in event viewer as event ID: 2014

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...