
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎05-23-2018 09:07 AM
We are currently implementing LogRhythm as our SIEM tool. Information gathered by LANSweeper (both metadata from LS itself and inventory data from scanned assets) would be of use in this environment.
Does anyone have any experience of integrating LS with a SIEM tool? Are there any obvious log sources we could tap into?
Grateful for anyone's thoughts.
Does anyone have any experience of integrating LS with a SIEM tool? Are there any obvious log sources we could tap into?
Grateful for anyone's thoughts.
Labels:
- Labels:
-
General Discussion
1 REPLY 1

Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎05-24-2018 09:32 AM
I'm not familiar with LogRhythm, but as far as logs go, Lansweeper will scan the Windows logs of computer's event log. By default only error events will be scanned, however you can also scan non-error events. If need be, you can also use the eventlog only scanning target to frequently rescan the eventlog of computers: https://www.lansweeper.com/kb/127/scanning-with-scheduled-eventlog-scanning.html
How to scan non-error events: https://www.lansweeper.com/kb/128/scanning-non-error-events.html
How to scan non-error events: https://www.lansweeper.com/kb/128/scanning-non-error-events.html
