Jump to content

Recommended Posts

Posted

Hello everyone!

 

We're looking at implementing some sort of centralised logging on our Windows network.

 

A few things we're aware of that might be solutions:

  • Windows Event Collector
  • LME (now deprecated)
  • Azure Sentinel

 

I suppose there's two 'problems' we're trying to solve:

  1. Enabling us to rapidly find out what happened in the event of a cyber attack.
  2. Analysis of the network health and picking up on issues before they become tickets.

 

Would be very interested to hear what other people are using, what benefits they are seeing from them, and what some realistic costs should be.

 

Any pointers are most appreciated! Thanks!

Posted
Hello everyone!

 

We're looking at implementing some sort of centralised logging on our Windows network.

 

A few things we're aware of that might be solutions:

  • Windows Event Collector
  • LME (now deprecated)
  • Azure Sentinel

 

I suppose there's two 'problems' we're trying to solve:

  1. Enabling us to rapidly find out what happened in the event of a cyber attack.
  2. Analysis of the network health and picking up on issues before they become tickets.

 

Would be very interested to hear what other people are using, what benefits they are seeing from them, and what some realistic costs should be.

 

Any pointers are most appreciated! Thanks!

 

Yea we tried to use LME with the use of slack ? I think it was.. the ncsc had a guide which was ok but just flaky and very overwhelming of information with no real way structure of the data, not very easily anyway, I’d be quite interested of other peoples views and setups on this topic

 

Thanks

Posted

I have set up a Graylog server here, with an OpenSearch server behind it, and then have Beats winlogbeat sending logs from a couple of servers, plus a syslog input to get some data from our firewall etc...

 

Early days at the moment. Its a complicated system with total flexibility in what it does.

 

At some point I'll sit down and set up some alerts - there's a plugin for Teams, so we could theoretically get it to post alert notifications there.

  • Thanks 1
Posted
I set up windows event forwarding for applocker logs to be sent to my log server - worked well untill deploying windows 11, the gpo caused explorer to hang, never got to the bottom of it.
Posted

*waves the Wazuh flag again*

 

https://wazuh.com

 

ELK stack (using Amazon's Elastic stack, which suffers less from dependency hell).

 

A ~1000 user secondary (with GPOs configuring event logs to log odd stuff) should probably assign 200GB of space for six months retention (all servers logging to Wazuh).

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...