Collecting local Windows logs

This use case scenario describes the settings required to collect logs from the host where the WinCollect Configuration Console is installed, and send them to IBM® QRadar®.


  1. Install the WinCollect Configuration Console on the host on which that you want to collect windows logs. Download the patch from IBM Support (
  2. Create a destination for the QRadar instance where you want to send WinCollect information. See Adding a destination to the WinCollect Configuration Console.
  3. Configure the local Microsoft event log device that is monitored. See Adding a device to the WinCollect Configuration Console.
    Important: In the Device Address field, type the IP address or hostname of the local Windows system that you want to poll for events.
  4. Click Deploy Changes under Actions.