WinCollect 101

Administrators can use WinCollect to capture Windows-based events for QRadar SIEM administrators.

What is WinCollect?

WinCollect is a Syslog event forwarder that administrators can use to forward events from Windows logs to QRadar®. WinCollect can collect events from systems locally or be configured to remotely poll other Windows systems for events. WinCollect uses the Windows Event Log API to gather events, and then WinCollect sends the events to QRadar.

IBM prides itself on delivering world class software support with highly skilled, customer-focused people. QRadar Support is available 24×7 for all high severity issues. For QRadar resources, technical help, guidance, and information, see our QRadar Support 101 pages.

Contact Support

Find your regional support contact