page-brochureware.php

WinCollect 101

Administrators can use WinCollect to capture Windows-based events for QRadar SIEM administrators. Use our 101 page to find information, ask us questions, view important notices, and review resources for WinCollect administrators.

What’s new in WinCollect 7.2.9?


New features are now provided to WinCollect users with the release of WinCollect 7.2.9:


  • Forwarded events now support filtering.
  • Windows Event Forwarding supports custom log source naming.
  • The File Forwarder plug-in now supports multi-line formatted logs.
  • Millisecond time format for event log collection
  • Standalone agents can now use TCP/514 to send heartbeat & status messages
  • WinCollect DHCP events now support Spanish/Polish language events
  • Support for NetApp 9.x.
  • Support for Windows Server 2019.
  • The limit of 10 queries in an XPath was removed.
  • Removed the MMC requirement from the WinCollect Standalone Patch Installer
  • Event Forwarding Sending to one log source support
  • Digitally signed installers

Supported versions

WinCollect is a Windows agent provided to QRadar administrators for the collection of Windows events in their networks. Administrators should be aware that supported software versions for IBM WinCollect is the latest version (n) and latest minus one (n-1). This means that the two newest versions of WinCollect (7.2.9-72 & 7.2.8-145) are the versions that QRadar Support will recommend with any support tickets (cases) that are opened against older versions. It is important for administrators to keep up-to-date with the latest releases as issues are fixed and new functionality released to improve collection of Windows events and keep up with Microsoft event logging protocol standards. WinCollect is not supported on version of Windows that are designated end-of-life by Microsoft. After software is beyond the Extended Support End Date, the product might still function as expected. However, IBM does not make code or vulnerability fixes to resolve WinCollect issues for older operating systems.

  • Windows Server 2019 (including Core)
  • Windows Server 2016 (including Core)
  • Windows Server 2012 (including Core)
  • Windows Server 2008 (including Core)
  • POSReady 7
  • Windows 10
  • Windows 8
  • Windows 7

Expert blogs

Bulk Editing in WinCollect & Log Source Management

Leverage the power of the Log Source Management app from the X-Force App Exchange to easily edit your WinCollect log sources.

Install WinCollect to Include XPath Queries

This blog post informs users how to install a Stand-alone WinCollect 7.2.8 agent from the command line to create a log source containing an XPath Query.

Install WinCollect to Include NSA Filters

How to install a Stand-alone WinCollect 7.2.8 agent from the command line to create a log source containing the NSA filter in your log source.

DNS Server Analytic WinCollect Configurations

This blog post guides administrators through a how-to administrators can follow when they attempt to configure WinCollect to collect DNS Server Analytic logs for the first time.

Stand-alone WinCollect and Template XML Installs

Templates allow administrators to deploy stand-alone agent configurations without having to manually alter the Agentconfig.xml or script changes.

Adding Device Types to Stand-alone WinCollect

This blog describes how to deploy an additional “plugin-in/service” without the need to install the stand-alone patch installer on each Windows host.

Watch the Latest WinCollect Open Mic

During this session we talk WinCollect overall, tools, notifications, troubleshooting tips, and round table your questions as they come in from the live audience for the webcast. The panelists for this session include the QRadar Development and Support teams. For a list of previous open mic sessions, see the full open mic list here.

IBM prides itself on delivering world class software support with highly skilled, customer-focused people. QRadar Support is available 24×7 for all high severity issues. For QRadar resources, technical help, guidance, and information see our QRadar Support 101 pages.