- play_arrow WinCollect 10 Overview
- play_arrow Installing WinCollect 10
- play_arrow Installing WinCollect 10
- Hardware and software requirements for the WinCollect 10 host
- Upgrading WinCollect 10 agents
- Installing WinCollect 10 using the GUI Quick installation
- Installing WinCollect 10 using the command line
- Installing WinCollect 10 using the Advanced installer
- WinCollect 10 Command line installation advanced examples
- WinCollect 10 installation script examples
- play_arrow Uninstalling WinCollect 10
- play_arrow WinCollect 10 Stand-alone Console
- play_arrow WinCollect 10 stand-alone console
- play_arrow WinCollect 10 stand-alone configuration
- play_arrow Agent settings
- Service status
- Log Viewer
- Top Sources
- Applying pending changes
- play_arrow Create a source in the Source wizard
- play_arrow Configuration Scripts
- play_arrow Configuration scripts
- Configuring WinCollect 10 to collect Microsoft security events
- play_arrow Agent configuration update script use cases
- Adding NSA filtering to an existing source
- Add Sysmon to your existing Windows event sources
- Changing the heartbeat interval
- Modifying the event data storage configuration
- Sending Syslog data to JSA over TCP
- Change the console port number
- Configuring a remote source with an update script
- Add Active Directory lookup update script
- Update script to add a secondary destination
- Update script file warn and error messages
- play_arrow Advanced Settings
- play_arrow Advanced settings
- Agent advanced settings
- play_arrow Source advanced settings
- Microsoft Windows events advanced settings
- EVTX Forwarder advanced settings
- Common file-based plugin advanced settings
- File Forwarder advanced settings
- Microsoft DHCP Server advanced settings
- Microsoft DNS Debug advanced settings
- Microsoft Exchange Server advanced settings
- Microsoft Forefront TMG advanced settings
- Microsoft IIS advanced settings
- Microsoft NPS advanced settings
- Microsoft SQL Server advanced settings
- System advanced settings
- play_arrow The WinCollect 10 Statistics File
- play_arrow WinCollect Terminology
Microsoft Windows Event source
You can use the Microsoft Windows Event source to collect events from standard Event logs (Application, System, and Security), as well as application and services logs (XPath).
Parameter | Description |
---|---|
Type | Microsoft Windows Events |
Channel | Select the channel that you would like to collect events from. Each channel that you want to collect from can be a unique source, or you can create an XPath query to collect from multiple channels.
|
Filter Enabled | You can use Pre-defined filters (such as NSA Filter) or other customer inclusion or exclusion filters. |
Supported versions of Microsoft Windows Event
The WinCollect Microsoft Windows Event plug-in is not supported on versions of Microsoft Windows Event that are designated end-of-life by Microsoft. After the software is beyond the Extended Support End Date, the product might still function as expected. However, Juniper does not make code or vulnerability fixes to resolve WinCollect issues for older software versions.
MSEVEN6 protocol
The WinCollect 10 Microsoft Windows Event source uses the MSEVEN6 protocol by default. Use MSEVEN6 Protocol for all Windows Event collection unless directed otherwise by Juniper Customer Support. If you have a specific use case that requires MSEVEN, contact Juniper Customer Support for instructions on how to switch your source and to provide a description of the value of your MSEVEN use case.