cancel
Showing results for 
Search instead for 
Did you mean: 

Integration issue on SIEM with windows

Hi

I have integrated my ESM with a high no of linux servers and other network devices, but off late there is high increase in requirment for windows integration.

I usually go for WMI when it comes to integration on windows , but i have realised that WMI is not working fine with windows 8.1 and above and windows server 2008 and above.

If any one have integrated and window server with mentioned version, please share the method.

Regards

Ravi

3 Replies
xded
Level 12
Report Inappropriate Content
Message 2 of 4

Re: Integration issue on SIEM with windows

Hi,

which rights have the user for the WMI connection? This User need full write and read rights for Windows Event Log.

Re: Integration issue on SIEM with windows

have provided complete rights to the user.

paul.k
Level 10
Report Inappropriate Content
Message 4 of 4

Re: Integration issue on SIEM with windows

Test is full admin rights (local as well) The none admin accounts seem to be a crapshoot.

Also RPC may not work with newer version of windows.

Regards

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator