Skip to content
  • There are no suggestions because the search field is empty.

How to collect windows powershell logs using winrm method in NetWitness

Issue

How to collect windows powershell logs using winrm method?


Resolution

In Windows server Event Viewer Navigate to Application and Service logs < >   >    Windows PowerShell
Copy the Log Name: Windows PowerShell as below.

User-added

On the NetWitness UI go to the Windows event collection channel in your Log collector  (Local and/or Remote, depending on your environment), add the channel as below:

User-added



Product Details

NetWitness Product Set: NetWitness Platform
NetWitness Product/Service Type: LogCollector 
NetWitness Version/Condition: 12.x
Platform: CentOS 7 / Alma

Approval Reviewer Queue

Technical approval queue