You can easily get WinCollect 10 up and running and sending events
to IBM®
QRadar® by selecting
Quick during the installation and specifying the QRadar appliance you want to send
your events to.
Procedure
-
Download the latest version of the WinCollect 10 agent.
- Launch a command prompt with administrative privileges.
- Run the following command and replace
WinCollect-10.X.X-X.x64.msi
with
the file from step 1.
msiexec.exe /i WinCollect-10.X.X-X.x64.msi
- In the Welcome to the IBM 64-bit Setup Wizard window, click
Next.
- Accept the EULA and click Next.
- In the Account Selection window, select to run the service as the
default account or a different account. When using a different account, enter the account domain and
name. On a regular system, the default account is the WinCollect virtual account. On domain
controllers, it is the LocalSystem.
- If the default account option was selected on a regular system, in the Virtual
Account window, select if you want to add the virtual account to the Administrators
group, then click Next. If the installation is on a Domain Controller, this
page is skipped .
- In the Installer Options window, select
Quick. The Quick installation option configures the agent to collect
Security, System, and Application events.
- In the Destination window, type in the hostname of the QRadar
appliance you want to send your WinCollect events to, and click Install.
- After the installation is complete, the Completing the IBM WinCollect Setup
Wizard window appears. Click Finish to close the installer.