Reader small image

You're reading from  Building a Next-Gen SOC with IBM QRadar

Product typeBook
Published inJun 2023
PublisherPackt
ISBN-139781801076029
Edition1st Edition
Right arrow
Author (1)
Ashish M Kothekar
Ashish M Kothekar
author image
Ashish M Kothekar

Ashish has a total experience of more than 15 years working for IBM on various different platforms. He is currently working as tech evangelist for IBM Security products. He has been instrumental in developing more than 10 IBM certification exams including IBM products like QRadar, Cloud Pak for Security, IBM SiteProtector, IBM XGS, etc. He has worked with multiple customers on deploying and then upgrading IBM security products. He has contributed regularly by writing blogs and giving talks on security products. He has published many redpapers on the integration of security products with IBM Storage solutions like IBM Spectrum scale. These redpapers are now full-fledged solutions that are being sold. He has also cleared two Mandarin language exams and is HSK2 qualified.
Read more about Ashish M Kothekar

Right arrow

WinCollect – the Agent for Windows

Over the years, there has been no other operating system as popular as the Windows operating system. In the recent past, many IT professionals have adopted Linux over Windows, but still, most machines run on the Windows operating system.

When we think of SIEM and the number of endpoints any SIEM will cater to, we know that the majority of these endpoints will be Microsoft Windows machines. Whether on enterprise servers or desktops, the Windows operating system is popular worldwide.

To cater to this requirement, the IBM QRadar team came up with a Windows-specific agent. This agent is known as WinCollect. In this chapter, we will understand the fundamentals of WinCollect, which will be detailed under the following topics:

  • Understanding WinCollect
  • Types of WinCollect agents
  • Tuning WinCollect

Understanding WinCollect

The WinCollect agent can provide centralized log management, highly customized log collection, and security monitoring for all Windows machines. WinCollect can also help us to collect logs from machines by polling logs.

WinCollect can be installed on a Windows machine, and it can even remotely poll events from other Windows machines in a network. These polled events can then be sent to QRadar. Typically, on Windows machines, the types of logs present are application logs, security logs, system logs, custom logs, and so on. It completely depends on the role of the Windows machine. If it is configured as a web server, then there is another category of logs added, called Internet Information Service (IIS) logs. So, depending on the services configured and running on a Windows machine, different types of logs can be collected by the WinCollect agent. WinCollect has pre-configured settings to collect Windows data and forward it to QRadar.

The WinCollect agent...

The types of WinCollect agents

Mostly, the WinCollect agent is used for centrally managing event data collection from Windows machines. But, you should know that there are two types of WinCollect agents. One is the widely used Managed WinCollect and the other is the Standalone WinCollect agent. The basic difference between the managed and standalone WinCollect agents is that managed WinCollect agents can be configured and updated from the QRadar GUI and for standalone agents, the configuration must be done locally on the Windows machine where it is installed. Standalone WinCollect agents come with a Java program that helps to configure agents on Windows machines directly.

Let us understand with examples how managed WinCollect agents work.

Managed WinCollect agents

In the following diagram, we see an implementation of the WinCollect agent in managed mode. We can see that the WinCollect agent is installed on a Windows machine.

Figure 11.1 – Managed WinCollect agent with remote polling

Figure 11.1 –...

Tuning WinCollect

WinCollect comes with many configurable parameters. It has different tuning profiles, polling intervals, and a number of channels. All this is made available to the user to choose the correct option for the amount of data that needs to be collected either from the Windows machine or remotely pulled from other Windows machines.

There are three important parameters for the tuning of WinCollect:

  • Event Rate Tuning Profile: We know that Windows machines could be our endpoint desktops or could be servers. On servers, there could also be different types of servers. Some could be email servers, web servers, or even DNS servers.

Depending on the number of events generated per second by a Windows machine, the categorization is as follows:

  • Windows Endpoint Default: These are the endpoint desktop machines that produce the lowest number of events per second.
  • Typical Server: These are typical servers that generate more events than endpoints. These...

Summary

WinCollect agents make it easier for QRadar admins to collect required data from Windows machines. Using other protocols such as MSRPC may present certain challenges, which are then addressed using WinCollect agents. Therefore, to collect events from Windows machines, the WinCollect agent is the recommended solution. In this chapter, we have seen different types of WinCollect agents and understood the different scenarios to use them in. In addition, we have dug deep into tuning the WinCollect agent for optimal performance.

In the next chapter, which will be the last chapter of the book, we will cover QRadar troubleshooting, frequently asked questions about QRadar, and the next-generation look of QRadar.

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Building a Next-Gen SOC with IBM QRadar
Published in: Jun 2023Publisher: PacktISBN-13: 9781801076029
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime

Author (1)

author image
Ashish M Kothekar

Ashish has a total experience of more than 15 years working for IBM on various different platforms. He is currently working as tech evangelist for IBM Security products. He has been instrumental in developing more than 10 IBM certification exams including IBM products like QRadar, Cloud Pak for Security, IBM SiteProtector, IBM XGS, etc. He has worked with multiple customers on deploying and then upgrading IBM security products. He has contributed regularly by writing blogs and giving talks on security products. He has published many redpapers on the integration of security products with IBM Storage solutions like IBM Spectrum scale. These redpapers are now full-fledged solutions that are being sold. He has also cleared two Mandarin language exams and is HSK2 qualified.
Read more about Ashish M Kothekar