We are integrating Windows servers with McAfee ESM-SIEM using WMI method. We are able to capture all the events that are logged in the Event Viewer of the windows server. However we are unable to captures events that are logged in Group Policy Management console of a windows Domain Control server.
Has anyone come across this kind of situation? Were you able to resolve it, if so please suggest on how to capture the events that are logged during Group Policy modifications.
We would like to capture the events that are logged when any Group Policy changes are made on the DC/AD in McAfee ESM (SIEM)
Thanks in advance.