Forward Windows events using Rsyslog to Wazuh


Pre-requisites:

Wazuh Configuration:

Open a syslog listener by adding the below configuration allowing to receive syslog data from the network subnet (Where my Windows server is located) specified within the allowed-ips tag and restart for applying it:

  <remote>
   <connection>syslog</connection>
   <allowed-ips>192.168.121.0/24</allowed-ips>
  </remote>

Add a rule to capture the logs :

Note that for simplicity, I am using only a rule and not extracting any fields form the logs, if needed, you should create custom decoders/rules

<group name="Winsyslog,">
  <rule id="100410" level="3">
    <program_name>WindowsEventSysLog</program_name>
    <description>Windows syslog event group</description>
  </rule>
</group>

Rsyslog configuration:

Add a tag (using WindowsEventSyslog tag to match with the Wazuh rule) to distinguish the logs and select the Windows channel you want to monitor:

Specify the Wazuh manager IP and port that has Syslog connection open and listening:


The output format can be customized and to benefit from the default Wazuh pre-decoder, for that, you should choose legacy RFC 3164 format and UTF8 including BOM then start the collection:

Result:

All Windows events are captured from our Wazuh manager, An example of a logon window with the tag added:

,

67 responses to “Forward Windows events using Rsyslog to Wazuh”

  1. I got what you mean , appreciate it for putting up.Woh I am lucky to find this website through google. “It is a very hard undertaking to seek to please everybody.” by Publilius Syrus.

  2. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  3. Thank you for the sensible critique. Me & my neighbor were just preparing to do a little research on this. We got a grab a book from our area library but I think I learned more from this post. I’m very glad to see such excellent information being shared freely out there.

  4. After going over a number of the blog articles on your web page, I seriously like your way of writing a blog. I saved as a favorite it to my bookmark website list and will be checking back in the near future. Please check out my website too and let me know how you feel.

  5. Good day very cool web site!! Guy .. Beautiful .. Amazing .. I’ll bookmark your site and take the feeds additionallyKI’m glad to find numerous useful info here in the post, we want work out extra strategies in this regard, thanks for sharing. . . . . .

  6. I’m amazed, I must say. Rarely do I come across a blog that’s both educative and engaging, and without a doubt, you’ve hit the nail on the head. The issue is something which too few folks are speaking intelligently about. I’m very happy I stumbled across this in my hunt for something relating to this.

  7. I loved as much as you will receive carried out right here. The sketch is attractive, your authored material stylish. nonetheless, you command get got an shakiness over that you wish be delivering the following. unwell unquestionably come further formerly again since exactly the same nearly very often inside case you shield this hike.

  8. “【超会議3特番】ボカロ感謝祭出演者&詳細発表”.神代にも「どんな状況下でも淡々と取引を行う精密機械のよう」とも言わしめたほどの実力者。 」は『土曜ワイド劇場』枠で放送するために2002年撮影されたが放映が延期され、2006年2月に昼間の『土曜サスペンス』の再放送枠で初放送された。 “『【出演】日本テレビ『有吉反省会 春の2時間スペシャル』』”.店内はコンビニエンスストアの様な照明にし、店舗面積を広めにとり、さらに商品の臭いを抜くための対策を施し、古本業界ではタブーであった立ち読みも可能にした。

  9. これにより、同行としては初となる空中店舗化された。 またシンボルマーク(小文字の「a」を2つ組み合わせたもの)の使用が開始された。財政赤字のイギリスが20に増税した2011年直後にイギリス人記者のコリン・ ミニストップに設置(後にファミリーマートも青森県内進出後に設置)。 2008年度以降は、テレビの中国語とハングル(以上は1年コース)を除いて、後期は再放送する。秋田銀行とATM相互無料開放(愛称はAAIネット)。北洋銀行・

Leave a Reply

Your email address will not be published. Required fields are marked *