Log Collection Windows: Step 2: Configure Windows Event Sources to Send Events to Security Analytics

Document created by RSA Information Design and Development on Jul 29, 2016
Version 1Show Document
  • View in full screen mode
 

This topic tells you where to find the event sources currently supported for Windows collection and the available configuration instructions for each event source.

Supported Event Sources List

Return toProcedures

The list of RSA Supported Event Sources is an alphabetized of all the event sources currently supported by Security Analytics that identifies which event sources you can use with Windows Collection.

  1. Find the name of the event source.
  2. Verify that it is supported by the Windows Collection Protocol.
  3. Click on to retrieve the configuration instructions for the event source.
  4. Verify that you downloaded the correct event source parser (for example, winevent_nic) from LIVE to the Log Decoder and enabled it.

Sample Configuration Instructions

The following illustration is taken from the Microsoft Windows Eventing 6.0 Web Services API configuration instructions.

WinConfigInstr.PNG 

You are here: Windows Collection Configuration Guide > Procedures > Log Collection Windows: Step 2: Configure Windows Event Sources to Send Events to Security Analytics

Attachments

    Outcomes