Hello,
Question if I may,
Given the architecture scenario:
(1)Event Source > (forwards events to) > (2)
WinCollect/Syslog Server > (3)
QRadar Event Processor > (4)
Qradar ConsoleIf the
QRadar Event Processor fails... will logs simply queue on
WinCollect Server; service is restored and all backlog from
WinCollect Server is then processed by
processor? Or will the
WinCollect Server drop logs?
thanks in advance.
My working assumption is that only failure on (2) (
WinCollect/Syslog Server) would result in data loss?