Skip to main content

Impelix IMPACT Integration
with Microsoft Windows Logs

The Impelix IMPACT platform ingests telemetry from your all your security products as well as third-party feeds (threat intelligence, cybersecurity risk, business resilience intelligence, etc.) and delivers event correlation, security control efficacy, and compliance monitoring.

We believe that the more data ingested into IMPACT, the more context you will have regarding security incidents, which will allow effective and efficient incident response and compliance management. Therefore, we encourage and facilitate connecting vendor products telemetry with Impelix IMPACT platform.

Microsoft Windows Logs

Winlogbeats
  1. Download Winlogbeats (OSS Version) from
    https://www.elastic.co/downloads/beats/winlogbeat-oss
  2. Extract the file from step 1 onto the Windows machine that will be sending logs to IMPACT.
    1. The directory can be placed anywhere on the filesystem.
  3. Edit the winlogbeat.yml within the extracted folder, as follows:
    1. Remove all content in the current file
    2. Copy and paste the example show below into the empty file
    3. Replace IMPACTIP with the IP address of the Impelix IMPACT server
    4. Save the file
  4. Execute the install-service-winlogbeat.ps1 file in the directory.
  5. Execute winlogbeat.exe in the file directory to start the service.
  6. Open the Services admin plugin in Windows and enable the Winbeats service and set it to start on boot.

winlogbeat.yml content: winlogbeat.event_logs: - name: Application ignore_older: 72h - name: Security - name: System event_logs.batch_read_size: 10 output.logstash: hosts: [IMPACTIP:5044] ssl.enabled: true ssl.verification_mode: none

The Next Evolution of SIEM

Avoid alert noise, high cost of data ingestion, and incident response complexity.
Move to our Automated SecOps and Enterprise Risk Management Platform.
✔︎ Respond     ✔︎ Investigate     ✔︎ Prevent     ✔︎ Comply
Schedule a Demo