Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows Defender Logs not wokring #6298

Closed
jeniha opened this issue Oct 15, 2020 · 4 comments
Closed

Windows Defender Logs not wokring #6298

jeniha opened this issue Oct 15, 2020 · 4 comments
Assignees

Comments

@jeniha
Copy link

jeniha commented Oct 15, 2020

Wazuh version Component Install type Install method Platform
unknown unknown unknown unknown unknown

Hi to all,
My issue is that:
Wazuh won`t grab logs from Windows Defender for exmaple:
when i turn off Real-time protection i cant see it in logs into wazuh, also when is scan a file and cant see is it a clean file.
Can you help me?

@jnasselle
Copy link
Member

Hi @jeniha ! In order to figure out where the problem is, could you please fill the table in the issue description with the information about your Wazuh installation? This will really help us.

@jeniha
Copy link
Author

jeniha commented Oct 16, 2020

I use .ova image and install new agent to new virtual machine with windows 10 for testing.
In ossec.conf in agent folder in Windows i put this code:

Microsoft-Windows-Windows Defender/Operational
<log_format>eventlog</log_format>

And in Security events event in web interface in wazuh cant show event from stoping Real-Time Proteciton or starting back up, even when find some virus there is no events from Defender.

@jeniha
Copy link
Author

jeniha commented Oct 16, 2020

Fixed:

Microsoft-Windows-Windows Defender/Operational
<log_format>eventchannel</log_format>

Victor Rebollo helps me in Slack

@jnasselle
Copy link
Member

Great news!
Despite both eventlog and evenchannel are supported by Wazuh, like the documentation mention, use Eventchannel for Windows Vista and later versions.

Regards,

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants