Global Security Forum

Security Global Forum

Our mission is to provide clients with an online user community of industry peers and IBM experts, to exchange tips and tricks, best practices, and product knowledge. We hope the information you find here helps you maximize the value of your IBM Security solutions.

 View Only
  • 1.  Wincollect agent: Remove Host

    Posted Tue April 26, 2022 04:35 AM

    Dear Community,

    I want to stop collecting remote windows logs from a log source.

    How can I remove a log source which is under a wincollect agent?  

    Thank you in advance.


    Best Regards,

    Michail Christof



    ------------------------------
    Michail Christof
    ------------------------------


  • 2.  RE: Wincollect agent: Remove Host

    Posted Thu April 28, 2022 01:29 PM
    Michail, not sure if this is is how-to question or you ran into some trouble(?)
    Is this a standalone or managed install? In case of a managed instance, you would do it - as for any other log source - using Log Source Management. In case of a standalone instance, you need to access the server where WinCollect is installed and use the console there (also, depending on the version - if it is v7 you would use a "traditional" app and if v10 there's a web app on localhost:3000 (example here)


    ------------------------------
    Dusan VIDOVIC
    ------------------------------



  • 3.  RE: Wincollect agent: Remove Host

    Posted Fri April 29, 2022 03:20 AM

    Thnaks Dusan.

    I am using managed installation and v7.
    From Log source management, if I disable a log source that using wincollect, it still continues sending logs to Qradar at SIM Generic.

    Kind Regards,

    Michail Christof



    ------------------------------
    Michail Christof
    ------------------------------



  • 4.  RE: Wincollect agent: Remove Host

    Posted Fri April 29, 2022 05:38 AM
    Hi Michail 

    You can disable the Wincollect agent in Qradar console UI 
    Admin > Data Sources > Wincollect > Agents 
    Please disable the agent that you are not collecting event from any more. 



    ------------------------------
    Brian Kwak
    ------------------------------