Can you please help to understand and resolve the issue.
Environment is like:
Multiple location (branches) having many on prem Win Servers where winlogbeat is installed and their we had dedicated on prem syslog servers respectively to forward logs to Elasticsearch.
Suddenly I noticed that from one specific location (branch) getting very less count of events. Earlier it was like hugh count.
Can someone please help me?