Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

How to get Windows 10 system with a Docker Container sending logs to the SEM?

$
0
0

We have a couple of Windows 10 workstations that are running Docker containers. The agents installs successfully on the base Windows systems and picks up the correct OS, IP address and License type (Workstation). The agents show online and have the normal four connectors running that our other Windows 10 systems have (Windows Active Response, Application Log, Security Log and System Log). But they do not have correct host name; instead they display with node name of host.docker.internal in place of the actual host name. Also the SEM does not have the log data from these Windows 10 workstations. If I look at the configuration of the Connectors, it is the same as on the Windows 10 systems that are reporting correctly, but are not running a Docker container. Is there a special configuration need for these systems?

 

At this point, we just want to collect the logs from the Windows 10 workstations. The Docker containers are just being used for testing/evaluation at the moment.

 

Thanks in advance for your help.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>