Jeremy Kerwin

Endpoint agents log collection to a VLC

Discussion created by Jeremy Kerwin on Jul 18, 2020
Latest reply on Jul 20, 2020 by Aaron Martin

We have a number of endpoints that exist in DMZ environments that are serviced by a VLC for log collection from syslog devices.

The hosts in the DMZ can only talk to the VLC and cannot talk back to any other NetWitness component, the VLC exists in a security zone that does have communication back to the core NetWitness components.

Is there, or will there be the capability to have Endpoint agents check in and send logs to VLCs? I know there is the Endpoint Relay Server but my understanding is that only gives endpoint data, it doesn't do log shipping?

Outcomes