As well known, the Safed agent for Windows can collect events from the event log, filters them and forward the matched records to a centralized syslog server. There are some preconfigured set of events concerning basic activities that have to be tracked.
The first one, and probably the most famous due to existing law conformity requirements deals with the tracking of Login/Logoff to the system. The second one it is worth to be pointed out is aimed at tracking process start/stop on Windows.
Indeed it is easy to set a rule for collecting and filtering events for all processes of interest with Safed. From the left side menu select “EventLog Objectives Configuration”, then add a new rule selecting the “Start or stop a process” option and filling the “General Search Term” field with the regular expression best matching your objective (Img. 1). All the rest is done by Safed, namely audit setting and data collecting, filtering and forwarding to the server.
Img. 1
On the server side all collected records (Img. 2) can be further filtered and correlated to obtain very interesting information about software use on windows systems (think about concurrent running instances licenses), and undesired or prohibited processes execution.
“Hi guys! I’m Mihail and since the university years I has been fascinated by distributed systems and measurements on them. Now when I join the Neteye project I get the possibility to continue with this passion and this is great. My free time is completely dedicated to my wife and my daughters, I simply love them.”
Author
MarinovMihail
“Hi guys! I’m Mihail and since the university years I has been fascinated by distributed systems and measurements on them. Now when I join the Neteye project I get the possibility to continue with this passion and this is great. My free time is completely dedicated to my wife and my daughters, I simply love them.”
Anyone who has joined the beautiful world of logging has collided, sooner or later, with the collection via syslog protocol. More than 40 years have passed since syslog was invented, and in that time there have been several attempts by Read More
Before I tell you about one of my latest customer requirements, I would like to briefly explain what our NetEye Tornado module is. In our user guide you will see it written that Tornado is the successor to NetEye's Event Read More
Creating hosts in NetEye’s Director module can sometimes be time-consuming and a repetitious, tiring and boring job. Especially if you have to populate Director with a large number of hosts for setting up a test environment, for example. One solution Read More
The Safed agent keeps track of the events it receives from the Eventlog by keeping the LastEventID in registry. At start time the agent tries to retrieve all events from Windows Eventlog since starting from the LastEventID. When the amount Read More
The Safed agent can be configured via https and send its collected logs to the log collector though a TLS connection. The latest released version - 1.9.1 - supports TLS 1.2 (at a minimum) and TLS 1.3. The first step Read More