Quantcast
Channel: Questions in topic: "universal-forwarder"
Viewing all articles
Browse latest Browse all 1551

Why is our universal forwarder not forwarding all logs on DHCP servers?

$
0
0
Hi DHCP Logs from all DHCP servers are not updating in Splunk, even though the logs are in present in there. When I restart the universal forwarder, I'm seeing the logs in Splunk. Is this the issue with forwarder? stanza in input.conf: [monitor://$WINDIR\System32\DHCP] disabled = 0 ignoreOlderThan=1d whitelist = DhcpSrvLog* crcSalt = sourcetype = DhcpSrvLog index = windows

Viewing all articles
Browse latest Browse all 1551

Trending Articles