Currently, the file connector has the capability to process rotating logs but that requires the ability to set up shares for Sentinel to access those logs remotely or develop a script to copy the logs to the local sentinel system or a common log repository.
If a customer has a locally installed Sentinel agent it should be able to handle rotating log files as well (ie. if the log file rotates and retains the same name). The agent currently only is able to handle situations where the new file that gets created has a different name.
by: Eric L. | over a year ago | Integrations
Comments
Eric, thanks for submitting this idea. We will look it over and let you know what our thoughts are. Or we may ask for additional information.
We are accepting this idea into our backlog. When it is planned for development, the status of the idea will be changed to "Planned".