please follow the following link... in your case, you need first to create a new device type using the DSM editor or you can use the Universal DSM in log source configuration.
Then, Create New log source:
set the Device Type to Universal DSM, or you can build new device type before start adding the log source as mentioned before.
Then select the protocol type as below:
Then you need to configure local collection as below (third configuration screen)
set the parameter as in the link provided.
------------------------------
ahmad zuhd
------------------------------
Original Message:
Sent: Wed September 08, 2021 02:54 PM
From: benlinux
Subject: How to use Wincollect to read Application logs
Hello experts,
How can I configure Wincollect to read logs from an application installed on a Windows host?
For example, I have an application "app1" that send its logs to a particular directory called C:\programs\app1\. How do i configure Wincollect to forward these logs to QRadar SIEM.?
Thank You.
------------------------------
benlinux
------------------------------