Sentinel Log forwarder dropping logs/events - How to prevent logs/event loss?


Hi There,

We have seen multiple cases where due to one reason or the other, Sentinel log forwarder drops logs/events. It can be due to below reasons:


1. OMS agent went to uninterrupted sleep state (This is an actual issue we identified on one of our clients)

2. Memory leakage issue (again identified the issue with one client)


Both these issues caused the events/logs to be dropped. Since log forwarder doesnt store these logs locally, is there any recommended architecture or method to ensure logs are not dropped.


We have clients who have strict compliance requirements and missing logs/events is not an option.


Any help will be appreciated.




1 Reply
Good day FahadAhmed, were you able to resolve this issue?