I want to transfer windows logs to LogRhythm SIEM, but I can't use logRhythm agent because it uses the PORT 445 which I don't want to open. I want to use Microsoft Sysmon. How to use it and which PORT it will use and is it secure?
I'm expecting a secure way to send Win Logs to LogRhythm SIEM
-
Sysmon is a system monitoring agent, not a log forwarding componentMathias R. Jessen– Mathias R. Jessen2024年01月31日 11:04:04 +00:00Commented Jan 31, 2024 at 11:04
-
so how to send logs collected by Sysmon to LogRhythm?Younes– Younes2024年01月31日 11:14:36 +00:00Commented Jan 31, 2024 at 11:14
-
Optimal solution depends on why you won't give LogRhytm access to fetch the events over RPC. What are you trying to defend against?Mathias R. Jessen– Mathias R. Jessen2024年01月31日 11:17:58 +00:00Commented Jan 31, 2024 at 11:17
-
It's in the organisation's policies. Is there a way to transfer windows logs securely to logRhythm without using the port 445?Younes– Younes2024年01月31日 12:07:50 +00:00Commented Jan 31, 2024 at 12:07
-
my own preference would be to use Windows' built-in event forwarding to centralize the events on a single box and the have LogRhythm collect them from that one box - then you only need a policy exception for 1 box instead of all of them :)Mathias R. Jessen– Mathias R. Jessen2024年01月31日 14:21:25 +00:00Commented Jan 31, 2024 at 14:21