WinRM Filtering

Yaarnaan 1 Reputation point
2020-07-28T15:31:06.77+00:00

Hello All,

I'm new to WinRM and the deployment, I have successfully made the Windows servers to log to a SIEM using WinRM, but I would like to know on how to filter out a particular event , using event ID as I don't want WinRM to send this event ID to my SIEM.

Remote Desktop
Remote Desktop
A Microsoft app that connects remotely to computers and to virtual apps and desktops.
4,284 questions
Windows Server Management
Windows Server Management
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Management: The act or process of organizing, handling, directing or controlling something.
423 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Jenny Yan-MSFT 9,326 Reputation points
    2020-07-29T07:54:36.847+00:00

    Hi,
    If you are using event forwarding to make the Windows servers to log to a SIEM using WinRM, you can define which events should be forwarded using the filter dialog in Event Viewer or with the XML query you see above for more advanced filters.
    https://serverfault.com/questions/913015/where-are-windows-event-forwarding-wef-subscriptions-filters-applied

    However the suppress statements which filter out specific events, only apply within that query statement and are not to the entire subscription.
    https://learn.microsoft.com/en-us/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection#baseline-subscription

    Please note: Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.

    Thanks,
    Jenny


  2. Jenny Yan-MSFT 9,326 Reputation points
    2020-07-31T02:32:59.07+00:00

    Hi,
    I am checking if there is more assistance needed for this thread.

    Please feel free to revert back and kindly Accept as answer if the information provided is helpful.

    Thanks,
    Jenny

    0 comments No comments