Can anyone help me determine if the logs in the elm.logs already processed by ERC. In our environment the ERC stopped collecting events at one point during investigation we saw that /var/log/data/inline/thirdparty.log/elm.logs directory is 100% utilized. Are the logs in this directory already processed by ERC (meaning to say, parsed, normalized) and ready to send to ESM. Im afraid that if I delete the logs under elm.logs to free up some utilization itl also delete the information meant for the ESM. Can someone confirm that if we delete the logs in elm.logs (raw logs) the data will be sent to ESM after the ERC can funtion again. Thanks.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.