You can use the Windows Event Collector (WEC) Sensor App to collect and store events from the computers in your network. When you use the WEC Sensor, the Windows Server machines function as the sender, and the Sensor itself functions as the collector. In most instances, it is recommended that you use the Windows Agent or the NXLogs plugin for Windows Event Log monitoring due to their enhanced performance and functionality.
Prerequisites for installation of the WEC sensor include these:
- Windows Server 2008, 2012, or 2019.
- PowerShell 3.0 or newer.
- A USM Anywhere Sensor with a private, static IP address, deployed in the same network forwarding logs to the sensor.
Installation and setup of the Sensor requires
- Windows Event Collector Setup.
- Windows Event Collector Log Forwarding.
- Windows Event Collector Sysmon Installation.
Related Video Content
To view other related training videos, click here.