Information Assurance Directorate Spotting the Adversary with Windows Event Log Monitoring |
|
Author:
| National Security Agency, |
ISBN: | 978-1-5085-3232-3 |
Publication Date: | Jun 2015 |
Publisher: | CreateSpace Independent Publishing Platform
|
Book Format: | Paperback |
List Price: | USD $15.99 |
Book Description:
|
It is increasingly difficult to detect malicious activity, which makes it extremely important to monitor and collect log data from as many useful sources as possible. This paper provides an introduction to collecting important Windows workstation event logs and storing them in a central location for easier searching and monitoring of network health. The focus of this guidance document is to assist United States Government and Department of Defense administrators in configuring central...
More DescriptionIt is increasingly difficult to detect malicious activity, which makes it extremely important to monitor and collect log data from as many useful sources as possible. This paper provides an introduction to collecting important Windows workstation event logs and storing them in a central location for easier searching and monitoring of network health. The focus of this guidance document is to assist United States Government and Department of Defense administrators in configuring central event log collection and recommend a basic set of events to collect on an enterprise network using Group Policy.