MYTHOSAI

Monitoring / PRACTICAL GUIDE

Check Wazuh Windows Event Channel collection

Confirm a specific Windows event channel reaches the manager before writing an alert rule.

Before you start

An enrolled Windows agent, authorised configuration access and access to relevant event logs.

Collection and alerting are separate

Wazuh must collect an event before a rule can analyse it. A rule might not generate an alert for every collected entry, and raw archives may not be enabled or indexed. Decide whether you are checking endpoint logging, agent collection or rule output; they are different stages.

Verify the source event locally

Open Event Viewer and inspect the relevant channel. For a failed-login exercise, confirm that Windows Security actually contains a suitable event and that auditing is configured. Do not repeatedly fail a production account to generate test data.

Review the existing collection configuration

Back up the agent configuration through your normal process and inspect existing localfile entries. A standard Event Channel entry has this structure:

xml
<localfile>
  <location>Security</location>
  <log_format>eventchannel</log_format>
</localfile>

Merge only what is missing into the appropriate ossec_config section. Do not duplicate an existing Security channel entry or overwrite unrelated collection settings. Group configuration may supply this centrally; choose one intended management route.

Test a narrow workflow

  1. Confirm the agent service runs and its local log has no relevant collection errors.
  2. Restart through the documented service process after a validated change.
  3. Generate or identify one harmless event within your approved lab procedure.
  4. Search the manager using agent identity, channel, event ID and an appropriate time window.

If it is not visible as an alert, investigate the decoder/rule path and your archive configuration. Do not enable extensive raw logging indefinitely just to produce one demonstration; it increases storage and privacy exposure.

Verify attribution

Compare the endpoint timestamp and identifying fields with the central event. Timezone display can differ from stored event time. Confirm the event belongs to the correct endpoint and has not been confused with an older duplicate agent.

Common mistakes

Installing the agent does not automatically meet every logging requirement. Enabling collection does not make Windows generate audit events it was not configured to create. A dashboard search with the wrong time range can look like a transport fault.

Protect the data

Security events can contain account names, hostnames and source addresses. Limit access and retention appropriately. Use dummy accounts and sanitised events in public teaching material. The successful outcome is a proven collection path for a specific event, followed by deliberate alert design.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.