Forum Discussion

AndrewX's avatar
AndrewX
Iron Contributor
Jul 29, 2019

Getting Windows Firewall Log into LA.

Hello - how do i get the C:\Windows\System32\LogFiles\Firewall\pfirewall.log into my Log Analytics, and which Table will it be ingested in?

 

I see a WindowsFirewall table, but that is empty.

 

WindowsFirewall
| limit 50

 

Over in LA advanced settings i see the option to add a custom log, which i did, but still no data.

 

Thoughts? 

11 Replies

    • AndrewX's avatar
      AndrewX
      Iron Contributor

      Hi CliveWatson - I was able to receive firewall connection logging by enabling the connector in Sentinel, this lit up the FirewallLog table in Log Analytics.  I am pretty sure the Windows Firewall Log you selected that is visible in event viewer is only for firewall administrative, changes, audit etc, but it does not list client connectivity.

      • JDP01's avatar
        JDP01
        Icon for Microsoft rankMicrosoft

        AndrewX 

         

        I just added in Sentinel then going into Log Analytics I can see Schema\Active\Windows Firewall is now there too. No data is there, so I'm assuming the Microsoft Monitoring Agent will automatically pick up the Windows Firewall Log %systemroot%\system32\LogFiles\Firewall\  if its enabled? I will most likely enable this in a WF Logging on a VM and see if the data starts to show up. Or is there more to configure so the MMA can find this log?

Resources