Event Collector for IIS logs keeps pulling old logs
After a recent re-configuration of the Event Collector, the system began to tail all the logs in a given directory as if the bookmarks for the tail entries had been reset. In our situation, these logs exist all the way back from 2017 which means our SIEM is also constantly alarming us that there is a health issue due to old logs being consumed. It almost seems like they're completely stuck on the 2017 logs and aren't processing anything new. Does anyone know how to correct this behavior assuming I cannot get the data owners/administrators to get rid of the logs from 2017-2019?
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.