Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Monitoring Windows Event Logs

$
0
0
Windows Event Log files (.evtx) monitoring stop working after a while and the Splunk universal forwarder has to be restarted to start data collection again. Here is the [monitor] stanza configured to monitor the Windows Event Log files (.evtx): [monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerActivity.evtx] disabled = 0 index = WinEvent [monitor://C:\Windows\System32\winevt\Logs\VisualSVNServerManagement.evtx] disabled = 0 index = WinEvent

Viewing all articles
Browse latest Browse all 47296


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>