Windows 365 Integration with Wazuh Manager

70 views
Skip to first unread message

Nithu Johnson

unread,
Aug 10, 2023, 3:59:15 PM8/10/23
to Wazuh mailing list
Hello Team,

I have a query concerning how to collect logs from Windows 365 for Wazuh. Scenario: Multiple users are utilizing the Cloud PC environment to access applications and their respective client environment. 

We need to retrieve Authentication and Access Logs, Application and Service Logs, Identity and User Activity Logs, Authentication and Identity Provider Logs, Audit Logs, and Endpoint Protection Logs, among others. 

Could you please provide guidance on how to fetch logs from the Cloud PCs?

Nicolas Zapata

unread,
Aug 11, 2023, 7:50:40 AM8/11/23
to Wazuh mailing list
Hi Nithu thanks for using wazuh!

To collect logs from Windows 365 for Wazuh, you can use the Wazuh module that allows you to collect all the logs from Office 365 using its API. The Office 365 logs conform to the JSON schema and Wazuh will automatically decode them, you can retrieve Authentication and Access Logs, Application and Service Logs, Identity and User Activity Logs, Authentication and Identity Provider Logs, Audit Logs, and Endpoint Protection Logs, among others

Then you can collect Windows logs, you can use the Log Data Collection capability of Wazuh. Wazuh can monitor classic Windows event logs, as well as the newer Windows event channels. To monitor a Windows event log, it is necessary to provide the format as "eventlog" and the location as the name of the event log. To monitor logs generated by a specific source with the eventchannel format, the configuration file should include the location of the source.
Regards
Reply all
Reply to author
Forward
0 new messages