Microsoft Windows Security Event Log

The IBM® QRadar® DSM for Microsoft Windows Security Event Log accepts syslog events from Microsoft Windows systems. All events, including Sysmon and winlogbeats.json, are supported.

Important: Support for the Windows Event Log protocols ended on 31 October 2022. To continue collecting Windows Event Log events, you must select a new protocol type from the list of supported protocols. For more information about the end of support, see QRadar: End of life announcement for WMI-based Microsoft Windows Security Event Log protocols (31 Oct 2022) (https://www.ibm.com/support/pages/node/6616223).
For event collection from Microsoft operating systems, QRadar supports the following protocols: