diff --git a/windows/security/threat-protection/windows-firewall/configure-the-windows-firewall-log.md b/windows/security/threat-protection/windows-firewall/configure-the-windows-firewall-log.md index ea78e8de16..96545288bd 100644 --- a/windows/security/threat-protection/windows-firewall/configure-the-windows-firewall-log.md +++ b/windows/security/threat-protection/windows-firewall/configure-the-windows-firewall-log.md @@ -54,3 +54,6 @@ To complete these procedures, you must be a member of the Domain Administrators - To create a log entry when Windows Defender Firewall allows an inbound connection, change **Log successful connections** to **Yes**. 6. Click **OK** twice. + +**Troubleshooting Slow Log Ingestion** + If logs are slow to appear in Sentinel, you can turn down the log file size. Just beware that this will result in more resource usage due to the increases resource usage for log rotation.