- play_arrow What's New in WinCollect
- play_arrow WinCollect Overview
- play_arrow Installation Prerequisites for WinCollect
- play_arrow Configuring WinCollect Agents After Installation
- Configuring WinCollect Agents After Installation
- Manually Adding a WinCollect Agent
- Deleting a WinCollect Agent
- WinCollect Destinations
- Adding Custom Entries to WinCollect Status Messages
- Forwarding Events Identifier
- Configuring Stand-alone WinCollect Agents with the Configuration Console
- Creating a WinCollect Credential
- Adding a Destination to the WinCollect Configuration Console
- Configuring a Destination with TLS in the WinCollect Configuration Console
- Adding a Device to the WinCollect Configuration Console
- Sending Encrypted Events to JSA
- Increasing UDP Payload Size
- Include Milliseconds in Event Log Timestamp
- Collecting Local Windows Logs
- Collecting Remote Windows Logs
- Changing configuration with Templates in a Stand-alone Deployment
- Configuration Options for Systems with Restricted Policies for Domain Controller Credentials
- play_arrow Log Sources for WinCollect Agents
- Log Sources for WinCollect Agents
- Windows Event Logs
- Microsoft DHCP Log Source Configuration Options
- Microsoft Exchange Server Log Source Configuration Options
- DNS Debug Log Source Configuration Options
- Collecting DNS Analytic Logs by Using XPath
- File Forwarder Log Source Configuration Options
- Microsoft IAS Log Source Configuration Options
- WinCollect Microsoft IIS Log Source Configuration Options
- Microsoft ISA Log Configuration Options
- Juniper Steel-Belted Radius Log Source Configuration Options
- Microsoft SQL Server Log Source Configuration Options
- NetApp Data ONTAP Configuration Options
- Configuring a TLS Log Source
- Adding a Log Source to a WinCollect Agent
- Bulk Log Sources for Remote Event Collection
- play_arrow Troubleshooting WinCollect Deployment Issues
- Troubleshooting WinCollect Deployment Issues
- Common Problems
- Replacing the Default Certificate in JSA Generates Invalid PEM Errors
- The Statistics Subsystem
- Event ID 1003 Splits the Message in JSA
- WinCollect Files are Not Restored During a Configuration Restore
- Windows 10 (1803) Cannot Read the Security Bookmark File
- Resolving Log Source Error After WinCollect Update
- WinCollect Log File
WinCollect Configuration Console Overview
In stand-alone deployments, use the WinCollect Configuration Console to manage your WinCollect deployment. Use the WinCollect Configuration Console to add devices that you want WinCollect to collect agents from, and add the JSA destination where you want to send events.
Prerequisites:
Before you can install the WinCollect Collect Configuration Console, you must do the following:
Install the WinCollect agent in stand-alone mode. For more information, see Installing the WinCollect Agent on a Windows Host.
Install .net framework version 3.5
Install Microsoft Management Console (MMC) 3.0 and later.
The following table describes the WinCollect Configuration Console.
Sections | Description |
---|---|
Global Configuration | The Global Configuration parameter allows you to view, add and update information about the system where WinCollect data is stored. |
Disk Manager— the path to the WinCollect Data, which is used to buffer events to disk when the event rate exceeds the event throttle. Capacity is the maximum capacity allowed for the contents of the Data Folder. WinCollect does not write to this folder after the maximum capacity is reached. | |
Installation Information— displays information about the WinCollect agent installation. Application Identifier— the header of the payload messages sent to the status server. Status Server— where the WinCollect Agent status events, such as heart beat messages and any warnings or errors generated by the WinCollect Agent, are sent. | |
Security Manager— centralized credentials, used to collect events from remote devices. | |
Destinations | The Destinations parameter defines where WinCollect device data is sent. |
Syslog TCP or Syslog UDP destinations include the following parameters: Name Hostname Port Throttle (events per second) You can expand a destination to view all devices that are assigned to the destination. | |
Devices | The Device parameter contains available device types. Under each device types, you can view or update multiple device parameters. |