Hi, First post here. I've just finished setting up my ELK stack and I've got a number of Windows servers forwarding their System, Application and Security logs. I'm looking to see if there's a way to delete the logs from my source servers after shipping them to my ELK stack. We have some old servers whose logs fill up and throw errors if they aren't cleared out.
This is not something that beats can do for you unfortunately.
You can configure this on your Windows servers. Go to Event Viewer and open the Properties of each log type, you should be able to overwrite old events or archive to local files.
That's what I thought. Thanks for confirming.
I knew about overwriting the logs, I was just curious if I could do it through beats. Thanks!
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.