Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Sending windows event to centralized source(Kiwi?) and then forwarding.

$
0
0

You may be able to use the windows centralization of event logs to accomplish this while the LEM team continues their work on native agentless collection. This piggybacks on winrm/windows remote management to forward events to a central windows event log server that you'd then have the LEM agent on. I'd test this with a couple of systems first to make sure that all the data gets reported correctly.

 

Configure Computers to Forward and Collect Events 

How to configure Windows Event Log Forwarding

 

You will be missing the ability to do active responses or USB device monitoring/protection without an agent (which is historically why LEM does not have an agentless collection method, not to mention agents have wavered from "no big deal" to "please god, no more agents" and back again over the course of time ).


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>