Hi,
I'm testing DLC log collection in the DMZ. To better understand the setup, our goal is to collect logs from endpoints (laptops) regardless of their location or VPN connection status - similar to how XDR/EDR agents send logs directly to the cloud.
We want to implement a similar approach, where agents forward their logs to the DLC using WinCollect (or maybe other solution).
In my opinion, the EC/EP setup is not as secure as the DLC for this purpose.
P.S. I understand that XDR/EDR solutions would handle log collection and aggregation more effectively, but let's assume XDR/EDR is not an option in this scenario.
BR
------------------------------
Vydenis Kucinskas
------------------------------
Original Message:
Sent: Fri October 10, 2025 09:39 AM
From: Perf1
Subject: DLC configuration
The main question is whether you really need a DLC.
QRadar has 3 collectors - EventCollector (EC), Disconnected Log Collector (DLC) and WinCollect. They have a lot in common and some differences. WinCollect is a collector agent, specifically for collecting Windows events. DLC is a lightweight general collector. EC is the most feature rich collector, which is also managed and has parsing and normalization built in.
While it is possible to send events from WinCollect to DLC to QRadar, there has to be a good reason to introduce this path and complexity. What are you trying to achieve?
------------------------------
Perf1
------------------------------