To migrate from Adaptive Log Exporter (ALE) deployments to WinCollect, install the WinCollect agent, create a log source, and
decommission ALE on the Windows host. The ALE product is
end of life (EOL), and is no longer supported.
Procedure
-
Install the WinCollect SFS on the IBM®
QRadar® SIEM Console.
-
Click the Admin tab.
-
From the Data Sources, click Wincollect.
-
On the WinCollect page, create a WinCollect destination by clicking .
-
Install the WinCollect agent on the Windows host. For more information, see Installing the WinCollect agent on a Windows host.
Note: You can create a log source from the WinCollect installation wizard.
-
Wait for the WinCollect agents to auto
discover.
-
Optional. Create a WinCollect log source in
QRadar to replace the existing log source that is used by
the Adaptive Log Exporter. For more information, see Adding a log source to a WinCollect agent.
Note: You can skip step 7 if Create Log Source was selected during the
installation of WinCollect. Log sources that use
the WinCollect protocol can be created
individually or added in bulk for WinCollect
agents that remotely poll for events.
-
In the Log Activity tab, verify that events are received.
-
Decommission the Adaptive Log Exporter:
-
Close all active applications on the Windows
host.
-
Open the Windows command prompt.
-
Go to the installation directory for the Adaptive Log Exporter.
Note: ALE standard installation directory is the Program Files or
Program Files (x86) directory.
-
To uninstall the Adaptive Log Exporter, type the following command:
unins000.exe /SILENT /VERYSILENT