Problems with Windows Event Collector

Eleonora Begisheva 5 Reputation points
2023-04-10T10:44:54.3233333+00:00

Good afternoon! There is a WEC server with several subscriptions for different logs (System, Security, Application). It works in Push mode with the event delivery optimization parameter "Minimal Latency". There are 6 DC connected to subscriptions. However, there are periodic delays in WEC receiving events from the Security log (there is a separate subscription for it). For example, the event is registered at 11:50 AM in the local log, but it only appears at 2:25PM on the WEC. 32GB of RAM is allocated for WEC, How to solve the problem?

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,311 questions
{count} vote