Integrating Splunk with native Windows Event Collection (WEC) and Optional 2-Stage Noise Filtering

4/25/2017 12:00:00 PM [(UTC-05:00) Eastern Time (US & Canada)] - Can't make the live event? Register anyway to receive a link to the recording.

Show/Hide All Time Zones

All Time Zones

Dateline Standard Time-(UTC-12:00) International Date Line West 4/25/2017 4:00:00 AM
UTC-11-(UTC-11:00) Coordinated Universal Time-11 4/25/2017 5:00:00 AM
Aleutian Standard Time-(UTC-10:00) Aleutian Islands 4/25/2017 7:00:00 AM
Hawaiian Standard Time-(UTC-10:00) Hawaii 4/25/2017 6:00:00 AM
Marquesas Standard Time-(UTC-09:30) Marquesas Islands 4/25/2017 6:30:00 AM
Alaskan Standard Time-(UTC-09:00) Alaska 4/25/2017 8:00:00 AM
UTC-09-(UTC-09:00) Coordinated Universal Time-09 4/25/2017 7:00:00 AM
Pacific Standard Time (Mexico)-(UTC-08:00) Baja California 4/25/2017 9:00:00 AM
UTC-08-(UTC-08:00) Coordinated Universal Time-08 4/25/2017 8:00:00 AM
Pacific Standard Time-(UTC-08:00) Pacific Time (US & Canada) 4/25/2017 9:00:00 AM
US Mountain Standard Time-(UTC-07:00) Arizona 4/25/2017 9:00:00 AM
Mountain Standard Time (Mexico)-(UTC-07:00) Chihuahua, La Paz, Mazatlan 4/25/2017 10:00:00 AM
Mountain Standard Time-(UTC-07:00) Mountain Time (US & Canada) 4/25/2017 10:00:00 AM
Central America Standard Time-(UTC-06:00) Central America 4/25/2017 10:00:00 AM
Central Standard Time-(UTC-06:00) Central Time (US & Canada) 4/25/2017 11:00:00 AM
Easter Island Standard Time-(UTC-06:00) Easter Island 4/25/2017 11:00:00 AM
Central Standard Time (Mexico)-(UTC-06:00) Guadalajara, Mexico City, Monterrey 4/25/2017 11:00:00 AM
Canada Central Standard Time-(UTC-06:00) Saskatchewan 4/25/2017 10:00:00 AM
SA Pacific Standard Time-(UTC-05:00) Bogota, Lima, Quito, Rio Branco 4/25/2017 11:00:00 AM
Eastern Standard Time (Mexico)-(UTC-05:00) Chetumal 4/25/2017 11:00:00 AM
Eastern Standard Time-(UTC-05:00) Eastern Time (US & Canada) 4/25/2017 12:00:00 PM
Haiti Standard Time-(UTC-05:00) Haiti 4/25/2017 11:00:00 AM
Cuba Standard Time-(UTC-05:00) Havana 4/25/2017 12:00:00 PM
US Eastern Standard Time-(UTC-05:00) Indiana (East) 4/25/2017 12:00:00 PM
Paraguay Standard Time-(UTC-04:00) Asuncion 4/25/2017 12:00:00 PM
Atlantic Standard Time-(UTC-04:00) Atlantic Time (Canada) 4/25/2017 1:00:00 PM
Venezuela Standard Time-(UTC-04:00) Caracas 4/25/2017 12:00:00 PM
Central Brazilian Standard Time-(UTC-04:00) Cuiaba 4/25/2017 12:00:00 PM
SA Western Standard Time-(UTC-04:00) Georgetown, La Paz, Manaus, San Juan 4/25/2017 12:00:00 PM
Pacific SA Standard Time-(UTC-04:00) Santiago 4/25/2017 1:00:00 PM
Turks And Caicos Standard Time-(UTC-04:00) Turks and Caicos 4/25/2017 12:00:00 PM
Newfoundland Standard Time-(UTC-03:30) Newfoundland 4/25/2017 1:30:00 PM
Tocantins Standard Time-(UTC-03:00) Araguaina 4/25/2017 1:00:00 PM
E. South America Standard Time-(UTC-03:00) Brasilia 4/25/2017 1:00:00 PM
SA Eastern Standard Time-(UTC-03:00) Cayenne, Fortaleza 4/25/2017 1:00:00 PM
Argentina Standard Time-(UTC-03:00) City of Buenos Aires 4/25/2017 1:00:00 PM
Greenland Standard Time-(UTC-03:00) Greenland 4/25/2017 2:00:00 PM
Montevideo Standard Time-(UTC-03:00) Montevideo 4/25/2017 1:00:00 PM
Saint Pierre Standard Time-(UTC-03:00) Saint Pierre and Miquelon 4/25/2017 2:00:00 PM
Bahia Standard Time-(UTC-03:00) Salvador 4/25/2017 1:00:00 PM
UTC-02-(UTC-02:00) Coordinated Universal Time-02 4/25/2017 2:00:00 PM
Mid-Atlantic Standard Time-(UTC-02:00) Mid-Atlantic - Old 4/25/2017 3:00:00 PM
Azores Standard Time-(UTC-01:00) Azores 4/25/2017 4:00:00 PM
Cape Verde Standard Time-(UTC-01:00) Cabo Verde Is. 4/25/2017 3:00:00 PM
UTC-(UTC) Coordinated Universal Time 4/25/2017 4:00:00 PM
Morocco Standard Time-(UTC+00:00) Casablanca 4/25/2017 5:00:00 PM
GMT Standard Time-(UTC+00:00) Dublin, Edinburgh, Lisbon, London 4/25/2017 5:00:00 PM
Greenwich Standard Time-(UTC+00:00) Monrovia, Reykjavik 4/25/2017 4:00:00 PM
W. Europe Standard Time-(UTC+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna 4/25/2017 6:00:00 PM
Central Europe Standard Time-(UTC+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague 4/25/2017 6:00:00 PM
Romance Standard Time-(UTC+01:00) Brussels, Copenhagen, Madrid, Paris 4/25/2017 6:00:00 PM
Central European Standard Time-(UTC+01:00) Sarajevo, Skopje, Warsaw, Zagreb 4/25/2017 6:00:00 PM
W. Central Africa Standard Time-(UTC+01:00) West Central Africa 4/25/2017 5:00:00 PM
Namibia Standard Time-(UTC+01:00) Windhoek 4/25/2017 5:00:00 PM
Jordan Standard Time-(UTC+02:00) Amman 4/25/2017 7:00:00 PM
GTB Standard Time-(UTC+02:00) Athens, Bucharest 4/25/2017 7:00:00 PM
Middle East Standard Time-(UTC+02:00) Beirut 4/25/2017 7:00:00 PM
Egypt Standard Time-(UTC+02:00) Cairo 4/25/2017 6:00:00 PM
E. Europe Standard Time-(UTC+02:00) Chisinau 4/25/2017 7:00:00 PM
Syria Standard Time-(UTC+02:00) Damascus 4/25/2017 7:00:00 PM
West Bank Standard Time-(UTC+02:00) Gaza, Hebron 4/25/2017 7:00:00 PM
South Africa Standard Time-(UTC+02:00) Harare, Pretoria 4/25/2017 6:00:00 PM
FLE Standard Time-(UTC+02:00) Helsinki, Kyiv, Riga, Sofia, Tallinn, Vilnius 4/25/2017 7:00:00 PM
Israel Standard Time-(UTC+02:00) Jerusalem 4/25/2017 7:00:00 PM
Kaliningrad Standard Time-(UTC+02:00) Kaliningrad 4/25/2017 6:00:00 PM
Libya Standard Time-(UTC+02:00) Tripoli 4/25/2017 6:00:00 PM
Arabic Standard Time-(UTC+03:00) Baghdad 4/25/2017 7:00:00 PM
Turkey Standard Time-(UTC+03:00) Istanbul 4/25/2017 7:00:00 PM
Arab Standard Time-(UTC+03:00) Kuwait, Riyadh 4/25/2017 7:00:00 PM
Belarus Standard Time-(UTC+03:00) Minsk 4/25/2017 7:00:00 PM
Russian Standard Time-(UTC+03:00) Moscow, St. Petersburg, Volgograd 4/25/2017 7:00:00 PM
E. Africa Standard Time-(UTC+03:00) Nairobi 4/25/2017 7:00:00 PM
Iran Standard Time-(UTC+03:30) Tehran 4/25/2017 8:30:00 PM
Arabian Standard Time-(UTC+04:00) Abu Dhabi, Muscat 4/25/2017 8:00:00 PM
Astrakhan Standard Time-(UTC+04:00) Astrakhan, Ulyanovsk 4/25/2017 8:00:00 PM
Azerbaijan Standard Time-(UTC+04:00) Baku 4/25/2017 8:00:00 PM
Russia Time Zone 3-(UTC+04:00) Izhevsk, Samara 4/25/2017 8:00:00 PM
Mauritius Standard Time-(UTC+04:00) Port Louis 4/25/2017 8:00:00 PM
Saratov Standard Time-(UTC+04:00) Saratov 4/25/2017 8:00:00 PM
Georgian Standard Time-(UTC+04:00) Tbilisi 4/25/2017 8:00:00 PM
Caucasus Standard Time-(UTC+04:00) Yerevan 4/25/2017 8:00:00 PM
Afghanistan Standard Time-(UTC+04:30) Kabul 4/25/2017 8:30:00 PM
West Asia Standard Time-(UTC+05:00) Ashgabat, Tashkent 4/25/2017 9:00:00 PM
Ekaterinburg Standard Time-(UTC+05:00) Ekaterinburg 4/25/2017 9:00:00 PM
Pakistan Standard Time-(UTC+05:00) Islamabad, Karachi 4/25/2017 9:00:00 PM
India Standard Time-(UTC+05:30) Chennai, Kolkata, Mumbai, New Delhi 4/25/2017 9:30:00 PM
Sri Lanka Standard Time-(UTC+05:30) Sri Jayawardenepura 4/25/2017 9:30:00 PM
Nepal Standard Time-(UTC+05:45) Kathmandu 4/25/2017 9:45:00 PM
Central Asia Standard Time-(UTC+06:00) Astana 4/25/2017 10:00:00 PM
Bangladesh Standard Time-(UTC+06:00) Dhaka 4/25/2017 10:00:00 PM
Omsk Standard Time-(UTC+06:00) Omsk 4/25/2017 10:00:00 PM
Myanmar Standard Time-(UTC+06:30) Yangon (Rangoon) 4/25/2017 10:30:00 PM
SE Asia Standard Time-(UTC+07:00) Bangkok, Hanoi, Jakarta 4/25/2017 11:00:00 PM
Altai Standard Time-(UTC+07:00) Barnaul, Gorno-Altaysk 4/25/2017 11:00:00 PM
W. Mongolia Standard Time-(UTC+07:00) Hovd 4/25/2017 11:00:00 PM
North Asia Standard Time-(UTC+07:00) Krasnoyarsk 4/25/2017 11:00:00 PM
N. Central Asia Standard Time-(UTC+07:00) Novosibirsk 4/25/2017 11:00:00 PM
Tomsk Standard Time-(UTC+07:00) Tomsk 4/25/2017 11:00:00 PM
China Standard Time-(UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi 4/26/2017 12:00:00 AM
North Asia East Standard Time-(UTC+08:00) Irkutsk 4/26/2017 12:00:00 AM
Singapore Standard Time-(UTC+08:00) Kuala Lumpur, Singapore 4/26/2017 12:00:00 AM
W. Australia Standard Time-(UTC+08:00) Perth 4/26/2017 12:00:00 AM
Taipei Standard Time-(UTC+08:00) Taipei 4/26/2017 12:00:00 AM
Ulaanbaatar Standard Time-(UTC+08:00) Ulaanbaatar 4/26/2017 12:00:00 AM
North Korea Standard Time-(UTC+08:30) Pyongyang 4/26/2017 12:30:00 AM
Aus Central W. Standard Time-(UTC+08:45) Eucla 4/26/2017 12:45:00 AM
Transbaikal Standard Time-(UTC+09:00) Chita 4/26/2017 1:00:00 AM
Tokyo Standard Time-(UTC+09:00) Osaka, Sapporo, Tokyo 4/26/2017 1:00:00 AM
Korea Standard Time-(UTC+09:00) Seoul 4/26/2017 1:00:00 AM
Yakutsk Standard Time-(UTC+09:00) Yakutsk 4/26/2017 1:00:00 AM
Cen. Australia Standard Time-(UTC+09:30) Adelaide 4/26/2017 1:30:00 AM
AUS Central Standard Time-(UTC+09:30) Darwin 4/26/2017 1:30:00 AM
E. Australia Standard Time-(UTC+10:00) Brisbane 4/26/2017 2:00:00 AM
AUS Eastern Standard Time-(UTC+10:00) Canberra, Melbourne, Sydney 4/26/2017 2:00:00 AM
West Pacific Standard Time-(UTC+10:00) Guam, Port Moresby 4/26/2017 2:00:00 AM
Tasmania Standard Time-(UTC+10:00) Hobart 4/26/2017 2:00:00 AM
Vladivostok Standard Time-(UTC+10:00) Vladivostok 4/26/2017 2:00:00 AM
Lord Howe Standard Time-(UTC+10:30) Lord Howe Island 4/26/2017 2:30:00 AM
Bougainville Standard Time-(UTC+11:00) Bougainville Island 4/26/2017 3:00:00 AM
Russia Time Zone 10-(UTC+11:00) Chokurdakh 4/26/2017 3:00:00 AM
Magadan Standard Time-(UTC+11:00) Magadan 4/26/2017 3:00:00 AM
Norfolk Standard Time-(UTC+11:00) Norfolk Island 4/26/2017 3:00:00 AM
Sakhalin Standard Time-(UTC+11:00) Sakhalin 4/26/2017 3:00:00 AM
Central Pacific Standard Time-(UTC+11:00) Solomon Is., New Caledonia 4/26/2017 3:00:00 AM
Russia Time Zone 11-(UTC+12:00) Anadyr, Petropavlovsk-Kamchatsky 4/26/2017 4:00:00 AM
New Zealand Standard Time-(UTC+12:00) Auckland, Wellington 4/26/2017 4:00:00 AM
UTC+12-(UTC+12:00) Coordinated Universal Time+12 4/26/2017 4:00:00 AM
Fiji Standard Time-(UTC+12:00) Fiji 4/26/2017 4:00:00 AM
Kamchatka Standard Time-(UTC+12:00) Petropavlovsk-Kamchatsky - Old 4/26/2017 5:00:00 AM
Chatham Islands Standard Time-(UTC+12:45) Chatham Islands 4/26/2017 4:45:00 AM
UTC+13-(UTC+13:00) Coordinated Universal Time+13 4/26/2017 5:00:00 AM
Tonga Standard Time-(UTC+13:00) Nuku'alofa 4/26/2017 5:00:00 AM
Samoa Standard Time-(UTC+13:00) Samoa 4/26/2017 5:00:00 AM
Line Islands Standard Time-(UTC+14:00) Kiritimati Island 4/26/2017 6:00:00 AM

Webinar Registration

Most of you have thousands of Windows systems. And many of you use Splunk.

  • Are you thinking of using native Windows Event Collection to improve and simplify getting those logs into Splunk with many Universal Forwarders and/or configuring them and the source computers for remote collection?
  • Did you try WEC and run into problems?
  • Would you like to monitor more Windows systems with Splunk but lack the budget for the increased indexing?
  • Are you already using WEC and Splunk and would like to share your tips and lessons learned?

Then this webinar is for you.

Windows native Event Collection (aka WEC or WEF) is awesome for getting those security logs on to one Windows event collector with zero-touch or agent installation on those thousands of source computers. But the next step is getting those events into your SIEM or log management solution. Here are few of the issues you may run in to:

  • SIEM doesn't recognize the ForwardedEvents log
  • SIEM doesn't understand that forwarded events are from many different systems and/or it's failing to look at the Computer Name field in the event header
  • Throughput issues with the volume of events on a Windows event collector
  • SIEM misidentifies the source type of the log and parses it incorrectly

In this first of a series on integrating various SIEMs and related solutions with WEC I'm going to cover all of these points and more.

After a very brief review of setting up Windows Event Collection (for more in depth treatment, see It's Time to Unleash the Power of Native Windows Event Collection) I will show you how to configure Splunk's Universal Forwarder to ship forwarded events from your Windows collector into Splunk. Here are some of the specific issues we'll discuss:

  • How to ensure forwarded security events are identical to the same events collected directly. This includes
    • ensuring sourcetype is correct and that events are parsed correctly so that all the WinEventLog:Security fields are present and your existing searches, reports, alerts continue to work
    • overriding the host field to use ComputerName
  • Why you need to send each WEC destination log only one source log type. This means you may need to create additional destination logs but this is not as simple as you might think. We'll show you how
  • Tips for handling the volume of events shipped to Splunk from WEC systems

Then we'll get into how to filter the noise from security logs before it gets indexed. No one wants to pay Splunk to index garbage or provide the hardware resources necessary to do so. You've got a number of options when it comes to noise filtering, including ways to address anxiety about filtering out events that you might later wish you had.

  • I'll show you what you can filter right at the source – before the noise ever leaves the system where it's generated.
  • Or go ahead and forward the full security log to your collector where you split the flow:
    • Archiving the raw logs in their entirety to cheap storage
    • Then filter the noise at the collector, before shipping to Splunk

I'll also identify an important limitation of WEC's Xpath filtering technology that makes it impossible to filter out a significant slice of security log noise and then show you how to address this with blacklist filters in Splunk.

LOGbinder's Supercharger for Windows Event Collection is our sponsor and you'll briefly see how Supercharger automates and centralizes the management, implementation and monitoring of Windows Event Collection.

If you use Splunk and you have Windows systems please join us for this specific and in-depth real training for free ™ session.

 
First Name:   
Last Name:   
Work Email:  
Job Title:  
Organization:  
Employees:  
How long have you been using native Windows Event Collection in production?:
How many Windows servers in your organization? :
 

Your information will be shared with the sponsor.