-
Book Overview & Buying
-
Table Of Contents
Building a Next-Gen SOC with IBM QRadar
By :
Mostly, the WinCollect agent is used for centrally managing event data collection from Windows machines. But, you should know that there are two types of WinCollect agents. One is the widely used Managed WinCollect and the other is the Standalone WinCollect agent. The basic difference between the managed and standalone WinCollect agents is that managed WinCollect agents can be configured and updated from the QRadar GUI and for standalone agents, the configuration must be done locally on the Windows machine where it is installed. Standalone WinCollect agents come with a Java program that helps to configure agents on Windows machines directly.
Let us understand with examples how managed WinCollect agents work.
In the following diagram, we see an implementation of the WinCollect agent in managed mode. We can see that the WinCollect agent is installed on a Windows machine.
Figure 11.1 –...
Change the font size
Change margin width
Change background colour