Passa al contenuto principale

5.1 How to configure Windows Event Logs collection

Configure the input options to enable SyskeyOT Windows Agent to collect Event Logs from the Windows machines.

Procedure

  1. In the top navigation pane, click on Events Log tab.

Event Log Tab

  1. Enable Log Collection – Click on Toggle switch to Enable/Disable EventLog collection of the local machine.
  2. Enable Facility Detection – Enable this feature to allow the agent to Auto Detect the Facility of the captured event logs.
  3. Default Facility - The default facility to be used when facility detection is not possible.
  4. Conversion Format – Configures how the event logs to be converted to. Please click the help button next to it for various options.
  5. Click Image Description