Skip to content
  • There are no suggestions because the search field is empty.

Configure Windows Event Sources

Configure Windows Event Sources in NetWitness

This topic tells you how to configure the Windows collection protocol.

In NetWitness, you need to configure the Kerberos Realm, and then add the Windows Event Source type.

To configure the Kerberos Realm for Windows collection:

  1. Go to netwitness_adminicon_25x22.png (Admin) > Services.
  2. Select a Log Collection service.
  3. Under Actions, select netwitness_ic-actns.png > View > Config to display the Log Collection configuration parameter tabs.
  4. Click the Event Sources tab.

    12.1_chooseCollectionMethod_1122.png

  5. Select Windows/Kerberos Realm from the drop-down menu.
  6. In the Kerberos Realm Configuration panel toolbar, click netwitness_ic-add.png to add a new realm.

    The Add Kerberos Domain dialog is displayed.

  7. Fill in the parameters, using the guidelines below.

  8. Click Save to add the Kerberos domain.

To add a Windows Event Source:

  1. Go to netwitness_adminicon_25x22.png (Admin) > Services.
  2. Select a Log Collection service.
  3. Under Actions, select netwitness_ic-actns.png > View > Config to display the Log Collection configuration parameter tabs.
  4. Click the Event Sources tab.

  1. In the Log Collector Event Sources tab, select Windows/Config from the drop-down menu.

    The Event Categories panel displays the VMware event sources that are configured, if any.

Next, continue from the current screen to add a Windows Event Category and type.

To configure the Windows Event Type:

  1. Select Windows/Config from the drop-down menu.

  2. In the Event Categories panel toolbar, click netwitness_ic-add.png to add a source.

    The Add Source dialog is displayed.

  3. Fill in the parameters, using the guidelines below.

  4. Click OK to add the source.

    The newly added Windows event source is displayed in the Event Categories panel.

  5. Select the new event source in the Event Categories panel.

    The Hosts panel is activated.

  6. Click netwitness_ic-add.png in the Hosts panel toolbar.
  7. Fill in the parameters, using the guidelines below.

  8. Click Test Connection.

    Note: You should be able to successfully test the connection, even if the Windows service is not running.

For more information on any of the previous steps, see the following Help topics in the NetWitness User Guide: