@hsynli wrote: Has there been an update and/or resolution to this issue? Or do we know the root of the issue? I have a similar, most probably the same issue. It seems to me Splunk forwarder stops sending logs when the defender platform or engine is updated (event codes 2002 and 2014, but not limited to). Logs start being sent to Splunk as soon as the splunkforwarder is restarted. That matches the issue. Fixed in 8.2.7 and above, and also in 9.0.0 and abovehttps://docs.splunk.com/Documentation/Splunk/8.2.7/ReleaseNotes/Fixedissues#Universal_forwarder_issues
... View more