Hi Faisal,
I am sorry for wrong expression. MSRPC is one of the log collection method but second option is installing a wincollect on a seperate server and you can collect Powershell logs with this wincollect server. There will be no agent on every server or client but just on wincollect server.
For MSRPC, as you mentioned there wouldn't be non-standard support:
https://www.ibm.com/support/pages/qradar-agentless-windows-events-collection-using-msrpc-protocol-msrpc-faq#logtypes
------------------------------
İsmail Kaya
------------------------------
Original Message:
Sent: Tue November 07, 2023 04:28 AM
From: Faisal Rafiq
Subject: IMPORTANT - Getting Application and Service Logs - Agentless
Hi Ismail,
But MSRPC protocol is only used to forward standard logs like application, security, and system logs. How can we set up using MSRPC to forward non-standard logs to IBM QRadar?
------------------------------
Faisal Rafiq
Original Message:
Sent: Tue November 07, 2023 02:22 AM
From: İsmail Kaya
Subject: IMPORTANT - Getting Application and Service Logs - Agentless
Hi Donald,
You can use MSRPC method as @JonathanPetcha mentioned. Also, you can use a seperate Windows server for remotely wincollect collection. You can use XPath Query different kind of logs like Powershell and Sysmon. Qradar support 10 different XPath query.

------------------------------
İsmail Kaya
Original Message:
Sent: Sun November 05, 2023 02:40 PM
From: Donald Lavag
Subject: IMPORTANT - Getting Application and Service Logs - Agentless
Hello Everyone,
i want to ask for your support to help me to find a way to fetch Sysmon and Powershell logs to QRadar without using WinCollect. i want to know if it is doable ? if yes, appreciate your kind support to help me to find a way to fetch Application and Service Logs from Event Viewer using MSRPC or WMI or any other way than WinCollect.
Thanks,
------------------------------
Donald Lavag
------------------------------