Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[winlogbeat] Try recovery from ERROR_INVALID_PARAMETER errors #39456

Open
marc-gr opened this issue May 8, 2024 · 1 comment
Open

[winlogbeat] Try recovery from ERROR_INVALID_PARAMETER errors #39456

marc-gr opened this issue May 8, 2024 · 1 comment
Labels
enhancement Team:Security-Windows Platform Windows Platform Team in Security Solution Winlogbeat

Comments

@marc-gr
Copy link
Contributor

marc-gr commented May 8, 2024

Describe the enhancement:

There are some situations where the event handle can be rendered invalid (ie automatic event log backups) and we will stop consuming events with an ERROR_INVALID_PARAMETER error.

We should be able to recreate the event handle when these errors occur to keep consuming.

Describe a specific use case for the enhancement or feature:

Systems with automatic backup will benefit from this, currently manual operation is required to restart winlogbeat.

NOTE: we should pay attention to not retry forever in case it keeps failing and be sure the current bookmarks in registry are valid to resume or they need to be deleted, etc.

@marc-gr marc-gr added enhancement Winlogbeat Team:Security-Windows Platform Windows Platform Team in Security Solution labels May 8, 2024
@elasticmachine
Copy link
Collaborator

Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement Team:Security-Windows Platform Windows Platform Team in Security Solution Winlogbeat
Projects
None yet
Development

No branches or pull requests

2 participants