Add Windows event logs
Follow this procedure to collect the standard Windows system, application, and security event logs through the OSSEC agent.
- In Threat Monitor, navigate to Admin > Manage Collectors.
- In the sensors list, select a collector, and then click Edit.
- Click the Syslog tab.
- Click the Log Destinations tab, and then click Add.
- In the Destination Setup window, select Both File and Elastic SOC.
- Enter a unique name based on the data source (winevtlog).
When entering a name, do not use spaces.
Delete the default log destination for winevtlog.
- Enter a file storage location on the collector, and then select the appropriate plugin.
This is typically located in /var/log/<filename>.log. For example, /var/log/winevtlog.log. You must specify a log destination for each plugin.
For collecting standard windows system, application, and security event logs, select the winevtlog (Windows Event Logs taken from Ossec) plugin.
- From the Process data for drop-down list, select your collector.
- Click the Actions tab, and then click Add.
The winevtlog filter is added by default.
- Add four rows, and then make the following selections from the Type and Value drop-down lists:
- Source: ossec
- Filter: winevtlog
- Destination: winevtlog (Elastic SOC)
- Destination: winevtlog (file)
- To save your settings, click Apply changes.
- Click the Data Sources tab.
- Click New Plugin.
- From the Active Plugin list, select winevtlog.
Click the gear icon next to each Play button under the Parser Workers, Storage workers, and Error Workers, and then click Save.
Please note that this is necessary to create the queues to process your incoming logs.
- For each queue, click Play.
- Set Parser Workers to 10, Storage Workers to 10, and then Error Workers to 5.
- Click Save.