LGrep implements syslog and Windows Event Forwarding (WEF) collectors, feeding data to Datalog analysis engine.
Open Local Group Policy Editor
(gpedit.msc
) and navigate to:
Local Computer Policy | +-Computer Configuration | +-Administrative Templates | +-Windows Components | +-Event Forwarding
Open Configure target Subscription Manager
:
-
Check
Enabled
-
Open
SubscriptionManagers
with theShow…
button -
Configure target subscription manager with the value:
Server=https://<FQDN/IP of collector>:5986/wsman/SubscriptionManager/WEC,Refresh=<seconds>,IssuerCA=<Thumbprint of the CA issuing TLS client authentication certificate>
winrm qc -transport:https