Skip to main content

@Lokesh_Dachepal If you don't want to use a SIEM product, you can always do Windows event forwarding to get all logs to a centralized place. https://learn.microsoft.com/en-us/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection#bkmk-appendixc

Be the first to reply!