Global Security Forum

 View Only
  • 1.  Wincollect agent: Remove Host

    Posted Tue April 26, 2022 04:35 AM

    Dear Community,

    I want to stop collecting remote windows logs from a log source.

    How can I remove a log source which is under a wincollect agent?  

    Thank you in advance.


    Best Regards,

    Michail Christof



    ------------------------------
    Michail Christof
    ------------------------------


  • 2.  RE: Wincollect agent: Remove Host

    Posted Thu April 28, 2022 01:29 PM
    Michail, not sure if this is is how-to question or you ran into some trouble(?)
    Is this a standalone or managed install? In case of a managed instance, you would do it - as for any other log source - using Log Source Management. In case of a standalone instance, you need to access the server where WinCollect is installed and use the console there (also, depending on the version - if it is v7 you would use a "traditional" app and if v10 there's a web app on localhost:3000 (example here)


    ------------------------------
    Dusan VIDOVIC
    ------------------------------



  • 3.  RE: Wincollect agent: Remove Host

    Posted Fri April 29, 2022 03:20 AM

    Thnaks Dusan.

    I am using managed installation and v7.
    From Log source management, if I disable a log source that using wincollect, it still continues sending logs to Qradar at SIM Generic.

    Kind Regards,

    Michail Christof



    ------------------------------
    Michail Christof
    ------------------------------



  • 4.  RE: Wincollect agent: Remove Host

    Posted Fri April 29, 2022 05:38 AM
    Hi Michail 

    You can disable the Wincollect agent in Qradar console UI 
    Admin > Data Sources > Wincollect > Agents 
    Please disable the agent that you are not collecting event from any more. 



    ------------------------------
    Brian Kwak
    ------------------------------