We are starting to see if LEM is a good solution for us. I am little concerned with this event. Does this mean that LEM lost 6256 audit events, and if it did is there anyway to find them?
The connector in that example is for a Windows Security log, so I'm guessing the machine under your scribble might be losing the events.
Is the source message a 4612?
Windows Security Log Event ID 4612 - Internal resources allocated for the queuing of audit messages have been exhausted,…
Retrieving data ...