I have deployed the agent along with the windows intergration. As part of this I wanted to collect Powershell logs.
This was working fine however at 20:31:49.750 yestarday I received my last powershell log on the "windows.powershell" data.stream.
No changes were made on the host side or for the elastic agent or policy. I can not find any explanation or error codes around this.
I have also taken a look at a seperate instance and it seems that the same has occured there i.e. the data stream was up and functioning and after a certain point no more powershell logs have been shipped.
Can anyone advise on where to look for an explanation for this and a potential fix ?
Thanks in advance.