Configuring Windows

Adding a Normalization Policy for Windows

  1. Go to Settings >> Configuration from the navigation bar and click Normalization Policies.

  2. Click Add.

  3. Enter a Policy Name.

  4. Select all the Compiled Normalizers and Normalization Packages applicable for Windows.

    DNSCompiledNormalizer supports the DNS logs with:

    • The ISO date format: YYYY/MM/DD.

    • The US date format: MM/DD/YYYY.

    DNSCompiledNormalizerEU supports DNS logs with:

    • The ISO date format: YYYY/MM/DD.

    • The European date format: DD/MM/YYYY.

Logpoint interprets the date format according to the selected compiled normalizer. We recommend you select compiled normalizer in the normalization policy based on your requirements.

Note

You must select the LPA_Windows compiled normalizer at last.

  1. Click Submit.

_images/windows_normpolicy.png

Adding a Normalization Policy

Adding Windows as a Device

  1. Go to Settings >> Configuration from the navigation bar and click Devices.

  2. Click Add.

_images/create_device.png

Adding Windows as a Device

  1. Enter a device Name.

  2. Enter the IP address(es) of the Windows server.

  3. Enter the Device Groups.

  4. Select an appropriate Log Collection Policy for the logs.

  5. Select a collector or a forwarder from the Distributed Collector.

Note

It is optional to select the Device Groups, the Log Collection Policy, and the Distributed Collector.

  1. Select a Time Zone. The timezone of the device must be the same as its log source.

  2. Configure the Risk Values for Confidentiality, Integrity, and Availability. These values are used to calculate the risk levels of the alerts generated from the device.

  3. Click Submit.

_images/available_collectorfetcher.png

Available Collectors and Fetchers

Configuring the Syslog Collector for Windows

  1. Go to Settings >> Configuration from the navigation bar and click Devices.

  2. Search for the previously added device.

  3. Click the Add icon from Actions.

  4. Click Syslog Collector.

_images/syslogcollector.png

Configuring Syslog Collector

  1. Select Syslog Parser as Parser.

  2. Select a Processing Policy that uses the previously created `normalization policy`_.

  3. Select the Charset.

  4. Select None in Proxy Server.

  5. Click Submit.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support