Hi
WMI / RECEIVER-
is the eazy way for collecting logs.
you just need to create a profile and then your entire domain could be monitored quickly
SIEM collector / agent -
is a bit more hard, becuase you need to install on every system you want to monitor
and dont forget the maintenence of all of the agents....
but, WMI will give you the basic OS platforme logs.
when you need more application level logs (e.g. Mail logs, SQL logs, sharepoint logs, IIS logs)
you will get it thees logs via SIEM Collector.
Best Regards👍👍👍
David