IBM EVTX Forwarder advanced settings
You can use the following advanced settings to fine tune IBM® EVTX Forwarder sources.
| Parameter | Default value | Description |
|---|---|---|
| Limit to supported EPS | true | When you use automatic tuning, the maximum tuning levels does not exceed the maximum supported EPS. |
| Identifier Override | hostname/IP | You can override the device identifier for this source. |
| Filename pattern | *.evtx | Only files that match this pattern are considered; this is an OS file filter. |
| Agent Device Type | WindowsLog | The AgentDevice field in the payload header. |
| Tuning Profile |
|
|
| Manual Tuning | ||
|
The length of time (milliseconds) between polls. | |
|
Maximum events to collect at each polling interval. | |
|
Number of events to fetch per call to the source. | |
| Event Levels |
|
|
| Keywords |
|
|
| Filter enabled | Checkbox | Turn the filter on or off. |
|
No Description | |
|
An Event filter | |
| SID Translation | Enabled | |
| Active Directory (AD) lookup | Not enabled | Turn the conversion of GUIDs into text on or off. |
| AD DNS domain name | ||
| AD domain controller name | ||
| Use Event Channel | Not enabled | Use the event's channel when available, and use Channel as the default. |