server logs export in CEF

ares 206 Reputation points
2021-01-13T18:11:38.553+00:00

Hi

I need to have all logs of about 10 servers be forwarded to a collector in cef format, any idea on how to achieve this?

can I use third party software of any kind?

thanks

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,499 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Dave Patrick 426.2K Reputation points MVP
    2021-01-13T18:38:06.03+00:00

    Something here may help.
    https://learn.microsoft.com/en-us/azure/sentinel/connect-common-event-format

    --please don't forget to Accept as answer if the reply is helpful--


  2. Xiaowei He 9,876 Reputation points
    2021-01-28T02:11:59.713+00:00

    Hi,

    After research, I didn't find information to transform windows event log to ref format, while below is the information about windows event forwarding, for your reference:

    https://learn.microsoft.com/en-us/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection

    Thanks for your time!
    Best Regards,
    Anne

    -----------------------------

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments