Windows event/device classification
I have a Windows Server 2008 sending logs to Envision. It was detected as unknown and I wish to manually set its device type but cannot determine whether to select "Windows Events (BL)", "Windows Events (ER)" or something else
Can someone shed some light on what the differences are between them?
The Windows device classification, unlike other event sources, is dependent upon the method used to transport the events to enVision. Windows Agentless collection (where enVision uses RPC calls to ge the event logs) is the most typical and is the "Windows Events (NIC)" type. Other methods include Snare "winevent_snare," Adiscon Event Reporter (winevent_er), and the new WinRM-based Windows Event Collection service (type I've forgotten at the moment).
More information is available in the Windows device configuration guide available on RSA's support site, SCOL.