Build Status | Branch |
---|---|
master | |
dev |
This module:
- automates set up of Windows Event Collector service with subscriptions based on Palantir's Windows-Event-Forwarding
- allows to send specific events based on definitions
-
This module relies on PSWinReporting to query EventLogs for specific events.
Make sure your:
- WEC sever is properly deployed,
- GPO in AD is created,
- Azure Workspace is prepared
- Then review examples and choose your style.
Finally set a schedule task on a server of your choice - it can be WEC server
itself or any other management server
with access to both Azure subcription and WEC server