Hi,
We are starting to see if LEM is a good solution for us. I am little concerned with this event. Does this mean that LEM lost 6256 audit events, and if it did is there anyway to find them?
Thanks,
-Pat
The connector in that example is for a Windows Security log, so I'm guessing the machine under your scribble might be losing the events.
Is the source message a 4612?
Windows Security Log Event ID 4612 - Internal resources allocated for the queuing of audit messages have been exhausted,…