Where does Splunk store the persistent queues for Windows logs. I am able to find the TCP and UDP queued logs but cannot find the Windows logs.
Hello there @reginaldsheetz_mantech
The path for PQs > $SPLUNK_HOME/var/run/splunk/[tcpin|udpin]/pq__<port>
Hello there @reginaldsheetz_mantech
The path for PQs > $SPLUNK_HOME/var/run/splunk/[tcpin|udpin]/pq__<port>