> Wow, thats a bit hostile. Sorry about that, it wasn't my intent. I was trying to determine if the change you made was something you got the ok with from Microsoft. My point is that you've increased the logging retention, are using a product that reads logs by design, and works fine when you delete the logs that are only there because you've increased the retention value. Once the firewall/agent completes the initial scan, it actually does start only where it left off. It has to succeed once though, so the logs you have might actually be ok. Try bumping the retry/reread value considerably for the first run. Once it completes, then you could probably lower that value to get faster responses to log changes.
... View more