Add Troubleshoot for Slow Firewall Log Ingestion

Added information about slow firewall log ingestion troubleshooting.
This commit is contained in:
YulelogPagoda 2019-11-19 15:25:19 +01:00 committed by GitHub
parent 0331b0cc15
commit 077cf6756e
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -54,3 +54,6 @@ To complete these procedures, you must be a member of the Domain Administrators
- To create a log entry when Windows Defender Firewall allows an inbound connection, change **Log successful connections** to **Yes**. - To create a log entry when Windows Defender Firewall allows an inbound connection, change **Log successful connections** to **Yes**.
6. Click **OK** twice. 6. Click **OK** twice.
**Troubleshooting Slow Log Ingestion**
If logs are slow to appear in Sentinel, you can turn down the log file size. Just beware that this will result in more resource usage due to the increases resource usage for log rotation.