LGrep implements syslog and Windows Event Forwarding (WEF) collectors, feeding data to Datalog analysis engine.
Open Local Group Policy Editor (gpedit.msc) and navigate to:
Local Computer Policy
|
+-Computer Configuration
|
+-Administrative Templates
|
+-Windows Components
|
+-Event Forwarding
Open Configure target Subscription Manager:
-
Check
Enabled -
Open
SubscriptionManagerswith theShow…button -
Configure target subscription manager with the value:
Server=https://<FQDN/IP of collector>:5986/wsman/SubscriptionManager/WEC,Refresh=<seconds>,IssuerCA=<Thumbprint of the CA issuing TLS client authentication certificate>
winrm qc -transport:https