- play_arrow WinCollect 10 Overview
- play_arrow Installing WinCollect 10
- play_arrow Installing WinCollect 10
- Hardware and software requirements for the WinCollect 10 host
- Upgrading WinCollect 10 agents
- Installing WinCollect 10 using the GUI Quick installation
- Installing WinCollect 10 using the command line
- Installing WinCollect 10 using the Advanced installer
- WinCollect 10 Command line installation advanced examples
- WinCollect 10 installation script examples
- play_arrow Uninstalling WinCollect 10
- play_arrow WinCollect 10 Stand-alone Console
- play_arrow WinCollect 10 stand-alone console
- play_arrow WinCollect 10 stand-alone configuration
- play_arrow Agent settings
- Service status
- Log Viewer
- Top Sources
- Applying pending changes
- play_arrow Create a source in the Source wizard
- play_arrow Configuration Scripts
- play_arrow Configuration scripts
- Configuring WinCollect 10 to collect Microsoft security events
- play_arrow Agent configuration update script use cases
- Adding NSA filtering to an existing source
- Add Sysmon to your existing Windows event sources
- Changing the heartbeat interval
- Modifying the event data storage configuration
- Sending Syslog data to JSA over TCP
- Change the console port number
- Configuring a remote source with an update script
- Add Active Directory lookup update script
- Update script to add a secondary destination
- Update script file warn and error messages
- play_arrow Advanced Settings
- play_arrow Advanced settings
- Agent advanced settings
- play_arrow Source advanced settings
- Microsoft Windows events advanced settings
- EVTX Forwarder advanced settings
- Common file-based plugin advanced settings
- File Forwarder advanced settings
- Microsoft DHCP Server advanced settings
- Microsoft DNS Debug advanced settings
- Microsoft Exchange Server advanced settings
- Microsoft Forefront TMG advanced settings
- Microsoft IIS advanced settings
- Microsoft NPS advanced settings
- Microsoft SQL Server advanced settings
- System advanced settings
- play_arrow The WinCollect 10 Statistics File
- play_arrow WinCollect Terminology
File Forwarder source
The File Forwarder source monitors many types of logs that are not covered as part of the standard WinCollect plug-ins. You can monitor logs continuously (Continuous Monitoring), or you can scan a folder for new files, process the contents, and wait for the next file (File Drop).
Because these logs fall outside of the standard plug-ins, there is no DSM to parse the events in JSA. You must either create a custom DSM or use the Universal DSM.
Parameter | Description |
---|---|
Type | File Forwarder |
Root directory | Directory where the log files that you want to pull data from are stored. Note: You no longer need to enter the UNC path for remote sources. |
Filename pattern | Only files that match this pattern are considered. This is an OS file
filter.*.* Will match all files *.log will match all files with a .log extenstion Server*.log will match all files with Server to start with and have.log extenstion |
Monitor subdirectories | Select if you would like the agent to monitor subdirectories of the root directory. |
Monitoring algorithm |
|