Home

Stale security event / Windows firewall reporting

%3CLINGO-SUB%20id%3D%22lingo-sub-1022900%22%20slang%3D%22en-US%22%3EStale%20security%20event%20%2F%20Windows%20firewall%20reporting%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1022900%22%20slang%3D%22en-US%22%3E%3CP%3EWondering%20if%20anyone%20has%20a%20solution%20they%20are%20happy%20with%20for%20monitoring%20stale%20security%20events%20and%20Windows%20firewall%20logs.%26nbsp%3B%20Not%20heartbeats%20or%20latest%20general%20response%2C%20but%20the%20specific%20event%2Flog%20collections%20to%20assure%20active%20collection%20from%20both%20sources.%26nbsp%3B%20Could%20do%20something%20like%20%22If%20a%20recent%20heartbeat%20received%20in%20the%20last%20%22x%22%20time%2C%20but%20no%20security%20or%20firewall%20events%20collected%20(separately)%20within%20%22y%22%20time%2C%20then%20report%20the%20computer.%22%26nbsp%3B%20Not%20sure%20how%20best%20to%20address%20normal%20computer%20downtime%20when%20monitoring%20PCs.%26nbsp%3B%20If%20a%20PC%20has%20been%20off%20all%20weekend%2C%20then%20would%20likely%20trigger%20a%20false%20alarm%20Monday%20morning%20due%20to%20the%20log%20ingestion%20delay.%26nbsp%3B%20Could%20extend%20%22y%22%20to%20be%20longer%20than%20the%20normal%20PC%20downtime%20scenarios%2C%20but%20wondered%20if%20anyone%20already%20had%20a%20more%20elegant%20solution%20in%20place%3F%26nbsp%3B%20Thx!%3C%2FP%3E%3C%2FLINGO-BODY%3E
g_mac
Regular Visitor

Wondering if anyone has a solution they are happy with for monitoring stale security events and Windows firewall logs.  Not heartbeats or latest general response, but the specific event/log collections to assure active collection from both sources.  Could do something like "If a recent heartbeat received in the last "x" time, but no security or firewall events collected (separately) within "y" time, then report the computer."  Not sure how best to address normal computer downtime when monitoring PCs.  If a PC has been off all weekend, then would likely trigger a false alarm Monday morning due to the log ingestion delay.  Could extend "y" to be longer than the normal PC downtime scenarios, but wondered if anyone already had a more elegant solution in place?  Thx!

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies