Jan 2020

February 2020 Newsletter

Download the eBook "Better SIEM Operations with Central Log Collection"

Download the latest eBook "Better SIEM Operations with Central Log Collection"

Microsoft System Center Configuration Manager

System Center Configuration Manager (SCCM) is a software management suite that enables administrators to manage the deployment and security of devices, applications and operating system patches.

NXLog can collect and forward the log data created by SCCM through:


Windows Event Log chapter about filtering for specific events

When dealing with a large volume of logs, and it is often necessary to collect a certain portion of events by implement filtering of events from the Windows Event Log. Use the Community/Enterprise Edition im_msvistalog module to:

  • Specify a specific channel to collect all the events written to a single channel. 

  • Add XPath query/queries to subscribe to events, subscribe to multiple channels and/or limit events by various attributes.

  • Read all events from a log file (for example, Security.evtx). This can be used for forensics purposes.

  • Configure for events to be discarded.

Discover what you can do to filter Windows events in our new section here.


Collecting Windows Update Logs

Windows Update is a Windows system service that manages the updates and patches for the Windows operating system. The event logs related to Windows Update can be collected using Event Tracing for Windows (ETW) or from the file system in older Windows versions via the WindowsUpdate.log file. Read the section here.


White Paper: Solving Windows Log Collection Challenges with Event Tracing

Event Tracing for Windows (ETW) logs kernel, application and other system activity. ETW provides better data and uses less resources. By understanding the key characteristics of ETW, system administrators can make a well informed decision on how to utilize the logs collected via ETW to improve IT Security. Read the whitepaper here or download the PDF.


Top Social Media Chatter in January/February

What did the community have to say about NXLog on social media?  Tweet to us, or shared your updates with us on LinkedIn for an opportunity to be listed in this newsletter.

Tweets

  • "Lovin’ your great documentation and capable product. Keep up the great work!" thanks @limpidweb !

Reddit Posts

Other places

Share this post