IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  MSRPC Group POlicy

    Posted Tue April 14, 2020 09:42 AM
    I'm using MSRPC to pull Windows server log to QRadar. Does anyone know which group policy settings to add Event Log Reader group to a global group policy setting? As of now, we keep adding the service account to the local event log reader group on the new host machine. This has been setup that way prior I came onboard and want to be more efficient using global policy instead of local policy.

    ------------------------------
    Hendry
    ------------------------------


  • 2.  RE: MSRPC Group POlicy

    Posted Wed April 15, 2020 09:34 AM
    MSRPC is OK to use for windows logs as long as no individual log source is generating above 50 EPS.

    ------------------------------
    Richard Gingras
    QRadar SME
    IBM Security
    Cambridge MA
    ------------------------------



  • 3.  RE: MSRPC Group POlicy

    Posted Wed April 15, 2020 12:05 PM
    Ok.

    What I'm trying to figure out is, where to assign/add Event Log Reader group in the gpo to deploy it to the windows server. Instead of adding the service account to the local event log reader group in each host.

    My suspicion is to add it to Computer Configuration > Policies > Windows Settings > Security Settings > Restricted Groups


    ------------------------------
    Hendry
    ------------------------------