In the event a forwarder crashed, let's say 24-48 hours of downtime.
- How can we recover the events that were meant to be ingested by the forwarder?
- How much data, in GB, will be ingested into CSIEM after the downtime? Is there a specific interval for this data transfer? If so, what is the volume of data sent to Chronicle?
- Once the events are ingested into CSIEM, how can we determine if any alerts were missed?
- Is there a method, either manual or automated, to validate whether any alerts were missed from the late ingested logs?
