Splunk and Windows Event Log: Best Practices, Reduction .
•Current_onlytells Splunk to only grab the latest events (like tail –f, if Windows had such a thing) •Useful to make sure you don’t get all the historical data •May want to set that to “true” on initial deployment •Then set to “false”, restart, and it should