Which architectural solutions would meet the client’s requirements?

During a new deployment, the client states that they want to collect windows logs and forward them to QRadar, but they are already using another agent to collect logs for a managed service provider [MSP] The client would like to continue forwarding these logs to the MSP as well as send them to QRadar.

Which architectural solutions would meet the client’s requirements?
A . Install an unmanaged Wincollect instance and a setup multiple forwarding destinations to the Wincollect configuration server.
B . Configure windows MSRPC protocol to send events to both.
C . Install a managed Wincollect instances and setup multiple forwarding destinations.
D . Configure Windows Event Forwarding to send events to both destinations.

Answer: B

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments