Microsoft Windows events advanced settings
You can use the following advanced settings to fine tune Microsoft Windows events sources.
Parameter | Default value | Description |
---|---|---|
Identifier Override | hostname/IP | You can override the device identifier for this source |
Tuning Profile |
|
|
Manual Tuning | ||
|
The length of time (milliseconds) between polls. | |
|
Maximum events to collect at each polling interval. | |
|
Number of events to fetch per call to the source. | |
Event Levels |
|
|
Keywords |
|
|
SID Translation | Enabled | |
Active Directory (AD) lookup | Not enabled |
Turn the conversion of GUIDs into text on or off. The lookup is performed by using the AD domain controller name if provided. If the AD domain controller name is not provided, it searches for a domain controller by using the AD DNS domain name. In either case, the credentials of the source device that is queried will be used to access the domain controller. If neither parameters are provided, the local machine is used to perform the lookup with no credentials. |
AD DNS domain name | ||
AD domain controller name |