Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to configure universal forwarders on roaming laptops to maintain Windows event logs to be forwarded once connected to our network?

$
0
0
I've installed a few Universal Forwarders on Windows laptops that are not consistently connected to the network. One machine did seem to cache events and forward them when reconnected, but another did not. My hypothesis is that this is because the first machine was only ever placed into hibernation, not shutdown or restarted, so the in-memory queue was preserved, whereas the other was shutdown. That said, I need to maintain these logs regardless of connectivity. From my research, I believe that two settings should achieve these goals: `useACK = true` in the output stanza, and `persistentQueueSize = 100MB` in each input stanza. This should cause all events to be written to disk until such time as the indexer is available. Is this a reasonable approach? I understand that there's some network and disk overhead involved, but is there any reason why this wouldn't work in the way I understand? Thanks for suggestions,

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>