2017-08-03 12:17 PM
Hi! I want to collect the events of a Microsoft DNS Server. But I don't want to collect the clients queries and server response, instead I want to collect the modifications that are made over the DNS Server, like an audit log. Is that possible? It must be done using winrm? any help is very appreciated.
2018-10-02 10:56 AM
I think this would be satisfied with the latest NW Endpoint agent collecting your local event channel
channel name
Microsoft-Windows-DNS-Server/Audit
Add that to the NW Endpoint agent config for channel capture to pull in the events via the Windows log parser following this method
2018-10-10 08:24 PM
Thank you so much Eric!