Skip to main content

Site CollectorSite Collector Administration Guide

Set Up Archive Windows Collector

Set up the Archive Windows Collector to collect log events from archived log files, *.gz, *.tar, *.tar.gz, *.gzip, *.rar, *.7z. The Archive Windows Collector is a set of Site Collector flows, pre-built processors, groups, custom processors, and other components that pull logs in plain text format and push the logs to Exabeam Security Operations Platform. The collector provides flexible template configuration capabilities to collect Windows events.

Tip

If you configure a Archive Windows Collector instance for a Site Collector instance which was created using a hostname, you may get a 'Request timed out' error while establishing communication with the host VM from a Windows VM. To avoid the 'Request timed out' error and ‘Setup error’, ensure that you complete the following steps on your Windows VM. 

Type ping hostnname_of_site_collector in your Windows command prompt. If this command succeeds, proceed with installing a Windows Collector for this Site Collector instance. If you get a ‘Request timed out’, or ‘Cannot resolve host’ or ‘Unknown host’ error, use the following steps.

  1. Open the hosts file that maintains mapping between hostname and IP_address, located at: C:\Windows\System32\drivers\etc\hosts, using Notepad.

  2. Add a new entry with your hostname and IP address at the end of the file for example, hostnname_of_site_collector  ip_address

  3. Save the hosts file.

  4. Proceed to install the Archive Windows Collector instance for this Site Collector instance.

To set up the Archive Windows Collector:

  1. Log in to the Exabeam Security Operations Platform with your registered credentials.

  2. Navigate to Collectors > Site Collectors.

  3. Ensure that Site Collector is installed and in running state.

  4. On the Site Collector page, click the Collectors Library tab, then click Archive Windows.

    Archive_Windows_logo_page.png
  5. In the Definition section, enter the required information as follows.

    Archive_Windows1.png
    • Collector Name – Site Collector generates a name for the Archive Windows collector based on your hostname.

    • Site Collector Instance – Select the site collector instance for which you want to set up the Archive Windows Collector. Only Site Collector instances on Site Collector version 1.17 and above are available.

  6. Click Next.

  7. In the Data section, set up the Windows template while configuring the collector. After you create a template, you can reuse the template for other collector instances or create a new template each time you set up a new Archive Windows Collector.

    Archive_Windows2.png
    • Archive Windows Template – Select a preconfigured template template to filter logs, or, create a new template. Templates enable you to filter logs by file names.

      Archive_Windows3_new_temp.png

      To create a new Archive Windows template:

      1. In the Templates list, click New Windows Template.

      2. In the Template Name field, specify a name for the new Windows template and click Next.

      3. In the Add File Paths section, for filtering logs, enable the log fields that you want to use by entering regex. Supported file extension formats are *.gz, *.tar, *.tar.gz, *.gzip, *.rar, and *.7z.

        • Include – Enter regex for the file names or paths to be included in log collection.

        • Exclude – Enter regex for the file names or paths to be rejected while collecting logs. The collector collects all the security events from the specified log name excluding the events or file names listed in this section.

          Archive_example.png
  8. In the Installation section, copy the scripts and download certificates as follows.

    Archive_Windows6.png
    • Certificate – Click Download Certificates to download the certificates. After you download the certificates, ensure that you save the certificates in the same directory from where you execute the installation command.

    • Install Script – Copy the Install script. Paste the script in the Powershell or cmd command line interface as an administrator where you put downloaded certificates. Then, run the copied command to install the Windows collector.

      Note

      You can use one install script for installing Archive Windows Collector on multiple Windows machines.

    • Uninstall Script – To uninstall the Archive Windows collector, copy and run the script using Powershell or cmd interface as an administrator. You must execute the script on the windows server.

  9. Verify that the Collector installed. After you run the Install script on your Windows server, you get a confirmation message about successful collector installation and the Collector instance is listed in the Overview section on the user interface.

    The Archive Windows Collector is set up and is ready to pull Windows events from your archived log files, *.gz, *.tar, *.tar.gz, *.gzip, *.rar, *.7z.

    After the Windows collector is set up, Site Collector Core starts pulling logs periodically based on your template configuration and uploads logs to Exabeam Security Operations Platform. If the Windows server is not available, Site Collector core resumes pulling logs from the place where it stopped.

    In case of installation failure, the collector is disabled, and the configuration is saved. You can check the status of the collector on the user interface or using the support package.

    Note

    The supported versions of Windows operating system are Windows 11, Windows 2016 and Windows Server 2016 core, Windows 2019 and Windows Server 2019 core, and Windows 2022 and Windows Server 2022 core.