F
F-Bob
I would like to use custom logs to forward windows events rather than sending everything to Forwarded Events. I have followed the instructions at this link:
as well as this:
My custom logs show up in Event Viewer and I am able to create a subscription and select the custom log as a destination. However, nothing is ever written to the custom log. In addition, nothing is recorded in the Microsoft-Windows-EventCollector-Operational log on the Collector or the Microsoft-Windows-Eventlog-ForwardingPlugin-Operational log on the forwarder. I feel as though I am missing some obvious point, although I can't find what that might be. The instructions in the links seem very straight forward. Has anyone done this and found what the 'secrect sauce' might be?
Continue reading...
Creating Custom Windows Event Forwarding Logs
blogs.technet.microsoft.com
Windows Event Forwarding for Network Defense
Incident detection and response across thousands of hosts requires a deep understanding of actions and behavior across users, applications…
medium.com
Continue reading...