WinCollect 101

Administrators can use WinCollect to capture Windows-based events for QRadar SIEM administrators.

What’s new in WinCollect 7.2.9 P1?

New features are now provided to WinCollect users with the release of WinCollect 7.2.9 P1:

  • FileForwarder allows empty lines within events when it uses the multiline byline parser.
  • DNS Lookup cache refreshed after a configurable amount of time to update asset IP addresses.
  • The File Forwarder plug-in now supports multi-line formatted logs.
  • All plugin dll’s now include with stand alone installer
  • See the WinCollect Release Notes for resolved issues

Download (QRadar 7.3.x)

Supported versions

WinCollect is a Windows agent provided to QRadar administrators for the collection of Windows events in their networks. Administrators should be aware that supported software versions for IBM WinCollect is the latest version (n) and latest minus one (n-1). This means that the two newest versions of WinCollect (7.2.9-96 & 7.2.9-72) are the versions that QRadar Support will recommend with any support tickets (cases) that are opened against older versions. It is important for administrators to keep up-to-date with the latest releases as issues are fixed and new functionality released to improve collection of Windows events and keep up with Microsoft event logging protocol standards. WinCollect is not supported on version of Windows that are designated end-of-life by Microsoft. After software is beyond the Extended Support End Date, the product might still function as expected. However, IBM does not make code or vulnerability fixes to resolve WinCollect issues for older operating systems.

  • Windows Server 2019 (including Core)
  • Windows Server 2016 (including Core)
  • Windows Server 2012 (including Core)
  • Windows 10
  • POSReady 7 (until 12 October 2021)
  • Windows 8.1 (until 1 January 2023)
  • Windows 7 (until 1 January 2023 with Extended Security Support)

Expert blogs

Bulk Editing in WinCollect & Log Source Management

Leverage the power of the Log Source Management app from the X-Force App Exchange to easily edit your WinCollect log sources.

Install WinCollect to Include XPath Queries

This blog post informs users how to install a Stand-alone WinCollect 7.2.8 agent from the command line to create a log source containing an XPath Query.

Install WinCollect to Include NSA Filters

How to install a Stand-alone WinCollect 7.2.8 agent from the command line to create a log source containing the NSA filter in your log source.

DNS Server Analytic WinCollect Configurations

This blog post guides administrators through a how-to administrators can follow when they attempt to configure WinCollect to collect DNS Server Analytic logs for the first time.

Stand-alone WinCollect and Template XML Installs

Templates allow administrators to deploy stand-alone agent configurations without having to manually alter the Agentconfig.xml or script changes.

Adding Device Types to Stand-alone WinCollect

This blog describes how to deploy an additional “plugin-in/service” without the need to install the stand-alone patch installer on each Windows host.

Watch the Latest WinCollect Open Mic

During this session we talk WinCollect overall, tools, notifications, troubleshooting tips, and round table your questions as they come in from the live audience for the webcast. The panelists for this session include the QRadar Development and Support teams. For a list of previous open mic sessions, see the full open mic list here.

IBM prides itself on delivering world class software support with highly skilled, customer-focused people. QRadar Support is available 24×7 for all high severity issues. For QRadar resources, technical help, guidance, and information, see our QRadar Support 101 pages.