Windows Event Logs

Posted 2 months ago by Jason Hall

Post a topic
Answered
J
Jason Hall

I have 2 Windows Server 2019 servers with the Windows Agent installed. I can see that it is pulling all the event logs through ok, but when i try and enable any integration that relies on the Windows Event logs i get the error "Windows events are not being logged"
When i look at the servers within data sources, the type is set to hids and doesnt include winevenlog. When i try to look at log-wineventlog-* in the log analyser it doesnt diplay anything, but i can see the event logs from winlogbeat in generic.

1 Votes

J

Juan Manuel Libera Frómeta posted 2 months ago Admin Best Answer

We recommend that you telnet from the windows server to the utmstack server.

The error message you are receiving suggests that the Windows Event Log service is not working properly. 

As an initial recommendation, we suggest you verify that the necessary ports for Windows Event Logs are open, including port 

5044/TCP used to send logs, 

1514-1516/TCP used for HIDS agent communications, 

55000/TCP used for the HIDS management API, and port 

9000/TCP used to connect to the agent manager. 


Checking and opening these ports may solve the problem.

If after verifying the ports and opening them the problem persists, please do not hesitate to contact us again so that we can continue to assist you. We will be happy to assist you in any way possible.

0 Votes


2 Comments

Sorted by
J

Jason Hall posted about 2 months ago

Hi, all the required ports were open and could telnet to them from the Windows Server to the UTM Server,

As a test installed an earlier version of the Windows Agent and this fixed the issue for all the servers. So it looks like the latest version of the agent wasn't working for me

0 Votes

J

Juan Manuel Libera Frómeta posted 2 months ago Admin Answer

We recommend that you telnet from the windows server to the utmstack server.

The error message you are receiving suggests that the Windows Event Log service is not working properly. 

As an initial recommendation, we suggest you verify that the necessary ports for Windows Event Logs are open, including port 

5044/TCP used to send logs, 

1514-1516/TCP used for HIDS agent communications, 

55000/TCP used for the HIDS management API, and port 

9000/TCP used to connect to the agent manager. 


Checking and opening these ports may solve the problem.

If after verifying the ports and opening them the problem persists, please do not hesitate to contact us again so that we can continue to assist you. We will be happy to assist you in any way possible.

0 Votes

Login or Sign up to post a comment