Thanks all, I've split out the Forwarded events and subscriptions to be more granular. And the dedicated sysmon channel + the TA is working well. I think we're roughly running 9 minutes behind. which isn't too bad, but i want to ensure we don't miss any logs. I'm still collecting some event IDs, but not seeing them in Splunk at all. I am seeing them in other solutions. Can i increase the cache size of the universal forwarder itself? I've increased the persistentCacheSize to 10GB, but unsure if i've set this property correctly or if it impacts the windows_TA Thanks
... View more