Monday, January 15, 2018

WinCollect - Agent Status

The Status Server is responsible for forwarding messages related to Agent status to QRadar. These LEEF messages can be easily viewed from the QRadar user interface from the WinCollect agent list using the Show Events button. These events are written in the C:\Program Files\IBM\WinCollect\logs\WinCollect_Device.log on the WinCollect agent and are also sent to the QRadar appliance as a LEEF syslog message.   

If you are troubleshooting why your Log Source - WinCollect is not sending any logs, the Agent status/event could help you to check the error  code.
In this example, one of my log source stopped sending log event using WinCollect

Procedure
  1. Log in to QRadar as an admin user.
  2. Click the Admin tab.
  3. Click the WinCollect icon.
  4. Select a WinCollect agent from the agent list.
  5. Click the Show Events icon


No comments:

Post a Comment

QRadar SIEM - Create a rule for Malware domain detection

In the previous post, I already created a Reference set for Malware domain. This time, we will create a rule when one of the malware domain...