Over the last three posts, we’ve looked at Microsoft event logging use cases and identified a set of must-have event IDs. Now we’re ready to put our security policy in place. This blog will walk you through configuring event logging on client workstations, and creating a subscription on a central log collection device.
Centralizing log collection removes the burden of having to log in to individual workstations during investigations. It also provides a way to archive log data for incident response or compliance requirements. Remember: being able to easily correlate activities across multiple hosts is a powerful threat detection and mitigation tool.
Configuring computers in a domain to forward and collect events
All source devices and the collector should be registered in the domain. 1.Enable Windows Remote Management Service on each source computer by typing the following at an administrator command prompt (select Run as Administrator from the Start menu or use the Runas command at a command prompt):winrm quickconfig
Note: It is a best practice to use a domain account with administrative privileges.
data:image/s3,"s3://crabby-images/8470b/8470b5967badfd50938bfaf90bb3a56f34ce60c8" alt=""
wecutil qc
3. Configure the Event Log Readers Group Once the commands have been run successfully, go back to the event source computer and open the Computer Management applet from the Server Manager:Click Start Right Click Computer Select Manage
Expand the Local Users and Groups option from the navigation pane and select the Groups folder. Select “Event Log Readers” group, right click and select Add.
data:image/s3,"s3://crabby-images/2f0da/2f0da9d8b4ef043ee37bb57d19c2ea31df34464d" alt=""
In the “Select Users, Computers, Service Accounts or Groups” dialog box, click on the “Object Type” button and select the checkbox for “Computers” and click OK.
Type in the name of the collector computer and click on the “Check Name” button. If the computer account is found, it will be confirmed with an underline.
The computers are now configured to forward and collect events.
4. Create a Subscription A subscription will allow you to specify the events you want to have forwarded to the collector. In the Event Viewer on the collector server, select the Subscriptions. From the Action menu in the right pane, choose the “Create Subscription…” link.data:image/s3,"s3://crabby-images/5caf4/5caf4402f172cb48346eddfebe809324dc995c31" alt=""
In the Subscription Properties dialog box:
a. Provide a name and description for the subscription. b. Leave the “Destination log” field set to default value of Forwarded Events. c. Choose the first option (“Collector initiated”) for subscription type and then click on Select Computers. d. Click on the “Add Domain Computers…” in the pop-up dialogue box. e. Type the name of the collector server and verify the name. Click OK twice to come back to the Subscription Properties main dialog box. f. In the Events to Collect section, click on the “Select Events…” button to bring up the Query Filter window.data:image/s3,"s3://crabby-images/39cf9/39cf97e9686a9889520ffe96de481b989ab12fb4" alt=""
data:image/s3,"s3://crabby-images/8cbcb/8cbcbcf0c2c894ef46eb79fc4f40ef23ceb5b38d" alt=""
Select the Forwarded Events option under Windows Logs in the Event Viewer.
Notes for Workgroups
If you want to set up log forwarding within a workgroup rather than a domain you will need to perform the following tasks in addition to those defined for domains:
- Add an account with administrator privileges to the Event Log Readers group on each source computer. You must specify this account in the dialog when creating a subscription on the collector computer. Select Specific User instead of Machine Account (see step 4j). You must also ensure the account is a member of the local Administrators group on each of the source computers.
- Type
winrm set winrm/config/client @{TrustedHosts="<sources>"}
<sources>
winrm set winrm/config/client @{TrustedHosts="msft*"}
on the collector computer. To learn more about this command, typewinrm help config.
Hopefully you have now built a working security policy using Windows Events. In the last blog of this series we will look at combining these events with other telemetry sources in a network by forwarding them to a syslog server or SIEM tool.