WinCollect 101

Administrators can use WinCollect to capture Windows-based events for QRadar SIEM administrators.

What’s new in WinCollect 7.2.9 P3?

New features are now provided to WinCollect users with the release of WinCollect 7.2.9 P3:

  • NOTE: An immediate fix to the .sfs patch installer was required therefore Patch 3 was released and replaces Patch 2
  • Microsoft DHCP and IIS fixes for high eps log collection
  • DNS Lookup fixed for Originating Computer
  • Fixed issue WinCollect Agents not receiving configuration updates with “Encrypt Host Connections” enabled in QRadar Settings
  • Several fixes to the Log Source Management App’s WinCollect Log Sources
  • See the WinCollect Release Notes for resolved issues

Download (QRadar 7.3.x)

Supported versions

WinCollect is a Windows agent provided to QRadar administrators for the collection of Windows events in their networks. Administrators should be aware that supported software versions for IBM WinCollect is the latest version (n) and latest minus one (n-1). This means that the two newest versions of WinCollect (7.2.9-105 & 7.2.9-96) are the versions that QRadar Support will recommend with any support tickets (cases) that are opened against older versions. It is important for administrators to keep up-to-date with the latest releases as issues are fixed and new functionality released to improve collection of Windows events and keep up with Microsoft event logging protocol standards. WinCollect is not supported on version of Windows that are designated end-of-life by Microsoft. After software is beyond the Extended Support End Date, the product might still function as expected. However, IBM does not make code or vulnerability fixes to resolve WinCollect issues for older operating systems.

  • Windows Server 2019 (including Core)
  • Windows Server 2016 (including Core)
  • Windows Server 2012 (including Core)
  • Windows 10
  • POSReady 7 (until 12 October 2021)
  • Windows 8.1 (until 1 January 2023)
  • Windows 7 (until 1 January 2023 with Extended Security Support)

Expert blogs

Bulk Editing in WinCollect & Log Source Management

Leverage the power of the Log Source Management app from the X-Force App Exchange to easily edit your WinCollect log sources.

Install WinCollect to Include XPath Queries

This blog post informs users how to install a Stand-alone WinCollect 7.2.8 agent from the command line to create a log source containing an XPath Query.

Install WinCollect to Include NSA Filters

How to install a Stand-alone WinCollect 7.2.8 agent from the command line to create a log source containing the NSA filter in your log source.

DNS Server Analytic WinCollect Configurations

This blog post guides administrators through a how-to administrators can follow when they attempt to configure WinCollect to collect DNS Server Analytic logs for the first time.

Stand-alone WinCollect and Template XML Installs

Templates allow administrators to deploy stand-alone agent configurations without having to manually alter the Agentconfig.xml or script changes.

Adding Device Types to Stand-alone WinCollect

This blog describes how to deploy an additional “plugin-in/service” without the need to install the stand-alone patch installer on each Windows host.

Watch the Latest WinCollect Open Mic

During this session we talk WinCollect overall, tools, notifications, troubleshooting tips, and round table your questions as they come in from the live audience for the webcast. The panelists for this session include the QRadar Development and Support teams. For a list of previous open mic sessions, see the full open mic list here.

Explore some of our other 101 pages. For a complete list, navigate from the top “101 Pages” menu.

IBM prides itself on delivering world class software support with highly skilled, customer-focused people. QRadar Support is available 24×7 for all high severity issues. For QRadar resources, technical help, guidance, and information, see our QRadar Support 101 pages.

Contact Support

Find your regional support contact