I discovered that one of the server running the Kiwi Syslog has its syslogd service stopped and not taking in logs from other servers. Checking Services.msc 'Kiwi Syslog Server' is still running while in Kiwi Syslog Service Manager showed 'The Kiwi Syslogd Service is stopped'. Checking Event Viewer found that the service stopped.
I've asked the server team if there was any activities during that period, there were SEP was being installed on all servers recently and scheduled full scanning were taking place. I've asked the server team to temporarily disabled scheduled full scanning and so far the service is running without any issues, however I do not want to conclude that SEP is the cause of the service to stop just yet. On average Kiwi Syslog pipes 1800K - 1900K MPH and at times can peak up to 2500K MPH. If it helps this is the hardware specs of the server.
Xeon E5-2680 2.40GHz
4GB RAM
Windows 2012 R2 64bit
1.5TB Storage
Does upgrading the RAM helps? Is there any other possible cause for the service stoppage?
Any and all help is greatly appreciated