Struggle with Winows event log collectors

Fabian 261 Reputation points
2020-09-24T16:09:15.75+00:00

Hi

Log collectors or SIEM tools are useful because the native Windows Event Viewer is slow, can search a limited number of logs only (around 4GB = 24h Security Log on DC), does not work across systems and cannot perform analysis or send alerts.

"Overwrite events as needed", is the best windows event log configuration for the collector to fetch as many events as possible. By design log collector tools can query the Windows event log by interval only. But an attacker can cover his tracks by creating many events to overwrite the relevant events. Even if the log is 4GB and the log collector fetches every minute, it is not guaranteed that the events are collected seamlessly.

"Archive the log when full", is the best configuration to seamlessly archive all events to file, even if an attacker penetrates the system. But the log collector has a cap between the last fetching and the time of archiving. E.g. 08:00 collector fetsches events, 08:05 Windows Event Log is archived to file, 08:10 collector fetsches again but the events between 08:00 and 08:05 are not collected because they are in the archive file.

How do I design a solution that allows events to be collected seamlessly without an attacker covering his tracks?
How does Microsoft's ATP?

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,524 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,775 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Jenny Yan-MSFT 9,326 Reputation points
    2020-09-25T02:38:51.257+00:00

    Hi,
    Kindly check if Windows Event Forwarding would help as instructed below:

    Use Windows Event Forwarding to help with intrusion detection
    https://video2.skills-academy.com/en-us/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection#how-frequently-are-wef-events-delivered

    As for window ATP, you could refer to below community for more details.
    Access the Microsoft Defender ATP Community Center
    https://techcommunity.microsoft.com/t5/microsoft-security-and/ct-p/MicrosoftSecurityandCompliance

    Thanks,
    Jenny