cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

Integration issue on SIEM with windows

Hi

I have integrated my ESM with a high no of linux servers and other network devices, but off late there is high increase in requirment for windows integration.

I usually go for WMI when it comes to integration on windows , but i have realised that WMI is not working fine with windows 8.1 and above and windows server 2008 and above.

If any one have integrated and window server with mentioned version, please share the method.

Regards

Ravi

3 Replies
xded
Level 12
Report Inappropriate Content
Message 2 of 4

Re: Integration issue on SIEM with windows

Hi,

which rights have the user for the WMI connection? This User need full write and read rights for Windows Event Log.

Re: Integration issue on SIEM with windows

have provided complete rights to the user.

paul.k
Level 10
Report Inappropriate Content
Message 4 of 4

Re: Integration issue on SIEM with windows

Test is full admin rights (local as well) The none admin accounts seem to be a crapshoot.

Also RPC may not work with newer version of windows.

Regards

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community