- play_arrow WinCollect 10 Overview
- play_arrow Installing WinCollect 10
- play_arrow Installing WinCollect 10
- Hardware and software requirements for the WinCollect 10 host
- Upgrading WinCollect 10 agents
- Installing WinCollect 10 using the GUI Quick installation
- Installing WinCollect 10 using the command line
- Installing WinCollect 10 using the Advanced installer
- WinCollect 10 Command line installation advanced examples
- WinCollect 10 installation script examples
- play_arrow Uninstalling WinCollect 10
- play_arrow WinCollect 10 Stand-alone Console
- play_arrow WinCollect 10 stand-alone console
- play_arrow WinCollect 10 stand-alone configuration
- play_arrow Agent settings
- Service status
- Log Viewer
- Top Sources
- Applying pending changes
- play_arrow Create a source in the Source wizard
- play_arrow Configuration Scripts
- play_arrow Configuration scripts
- Configuring WinCollect 10 to collect Microsoft security events
- play_arrow Agent configuration update script use cases
- Adding NSA filtering to an existing source
- Add Sysmon to your existing Windows event sources
- Changing the heartbeat interval
- Modifying the event data storage configuration
- Sending Syslog data to JSA over TCP
- Change the console port number
- Configuring a remote source with an update script
- Add Active Directory lookup update script
- Update script to add a secondary destination
- Update script file warn and error messages
- play_arrow WinCollect Sources
- play_arrow WinCollect Sources
- play_arrow The WinCollect 10 Statistics File
- play_arrow WinCollect Terminology
EVTX Forwarder advanced settings
You can use the following advanced settings to fine tune EVTX Forwarder sources.
EVTX Forwarder advanced settings
Parameter | Default value | Description | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Identifier Override | hostname/IP | You can override the device identifier for this source. | ||||||||||||
Filename pattern | *.evtx | Only files that match this pattern are considered; this is an OS file filter. | ||||||||||||
Agent Device Type | WindowsLog | The AgentDevice field in the payload header. | ||||||||||||
Tuning Profile |
|
| ||||||||||||
Manual Tuning | ||||||||||||||
| The length of time (milliseconds) between polls. | |||||||||||||
| Maximum events to collect at each polling interval. | |||||||||||||
| Number of events to fetch per call to the source. | |||||||||||||
Event Levels |
|
| ||||||||||||
Keywords |
|
| ||||||||||||
Filter enabled | Checkbox | Turn the filter on or off. | ||||||||||||
| No Description | |||||||||||||
| An Event filter | |||||||||||||
SID Translation | Enabled | |||||||||||||
Active Directory (AD) lookup | Not enabled | Turn the conversion of GUIDs into text on or off. | ||||||||||||
AD DNS domain name | ||||||||||||||
AD domain controller name | ||||||||||||||
Use Event Channel | Not enabled | Use the event's channel when available, and use Channel as the default. |