{"id":132,"date":"2023-05-01T22:29:46","date_gmt":"2023-05-01T22:29:46","guid":{"rendered":"https:\/\/canokar.com\/?p=132"},"modified":"2023-11-04T15:39:38","modified_gmt":"2023-11-04T15:39:38","slug":"microsoft-wef-yapilandirmasi-ve-logsign-siem-ile-entegrasyonu","status":"publish","type":"post","link":"https:\/\/canokar.com\/?p=132","title":{"rendered":"Microsoft WEF yap\u0131land\u0131rmas\u0131 ve Logsign Siem ile entegrasyonu"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<p>Merhaba bu yaz\u0131m\u0131zda test ortam\u0131m\u0131zda bulunan bir Windows 10 client\u2019\u0131n event loglar\u0131n\u0131 Microsoft\u2019un WEF yap\u0131land\u0131rmas\u0131n\u0131 kullanarak \u00f6nce WEF sunucumuza g\u00f6nderece\u011fiz ard\u0131ndan WEF sunucumuz \u00fczerinden NXLog ile Logsign Siem sunucumuza g\u00f6nderece\u011fiz.<\/p>\n\n\n\n<p>WEF bize ne sa\u011flaycak?<br>&#8211; WEF ile yap\u0131m\u0131zda bulunan makinelerin loglar\u0131n\u0131 bu makinelere ajan kurma gereksinimi duymadan bu makinelerin loglar\u0131n\u0131 sadece bir group policy arac\u0131l\u0131\u011f\u0131 ile merkezi bir noktaya y\u00f6nlendirebilece\u011fiz (WEF sunucu) ve siem \u00fczerinde tan\u0131ml\u0131 tek kaynak \u00fczerinden t\u00fcm bu makinelerin loglar\u0131na ula\u015fabilece\u011fiz.<\/p>\n\n\n\n<p>\u00d6ncelikle WEF sunucumuza ba\u011flan\u0131yoruz ve Event Viewer\u2019\u0131 a\u00e7\u0131yoruz. Subscription k\u0131sm\u0131na t\u0131klad\u0131\u011f\u0131m\u0131z zaman bize Windows Event Collector servisinin ba\u015flat\u0131laca\u011f\u0131n\u0131 ve enable edilece\u011fini s\u00f6yleyen bir uyar\u0131yla kar\u015f\u0131la\u015f\u0131yoruz ve evet diyoruz.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/1.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/1-1024x607.png\" alt=\"\" class=\"wp-image-133\" width=\"717\" height=\"425\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/1-1024x607.png 1024w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/1-300x178.png 300w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/1-768x455.png 768w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/1-1200x711.png 1200w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/1.png 1422w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/figure>\n\n\n\n<p>Ard\u0131ndan Windows Remote Management servisini ba\u015flat\u0131yoruz. Bu i\u015flemi servisler arac\u0131 \u00fczerinden de yapabiliriz. Ben Cli\u2019dan yapmay\u0131 tercih ettim o y\u00fczden \u015fu komuyu \u00e7al\u0131\u015ft\u0131r\u0131yorum.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>winrm quickconfig -quiet<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/2.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/2-1024x605.png\" alt=\"\" class=\"wp-image-137\" width=\"629\" height=\"371\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/2-1024x605.png 1024w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/2-300x177.png 300w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/2-768x454.png 768w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/2.png 1164w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Servisin zaten \u00e7al\u0131\u015ft\u0131\u011f\u0131n\u0131 g\u00f6r\u00fcyorum.<br>Bu servisin startup type\u2019\u0131n\u0131n Automatic oldu\u011fundan emin oluyorum.<\/p>\n\n\n\n<p>Ard\u0131ndan <em>wevtutil<\/em> ile kb cinsinden client loglar\u0131m\u0131z\u0131n birikece\u011fi Forwarded Events k\u0131sm\u0131n\u0131n maksimum log limitini art\u0131r\u0131yorum. Bu \u00f6rnekte yakla\u015f\u0131k 1 GB yapm\u0131\u015f olduk. &nbsp;Bu i\u015flem foto\u011frafta g\u00f6r\u00fclen Max Log Size k\u0131sm\u0131ndan da yap\u0131labilir. Girece\u011fimiz de\u011fer kb cinsinden 64\u2019\u00fcn katlar\u0131 olmal\u0131d\u0131r. E\u011fer de\u011filse Windows bu de\u011feri sizin i\u00e7in yuvarlayacakt\u0131r.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>wevtutil sl forwardedevents \/ms:1000000000<\/code><\/pre>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/3.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/3-1024x611.png\" alt=\"\" class=\"wp-image-145\" width=\"634\" height=\"374\"\/><\/a><\/figure><\/div>\n\n\n<p><\/p>\n\n\n\n<p>E\u011fer Windows Server 2016 veya 2019 kullan\u0131yorsan\u0131z Windows Remote Management i\u00e7in varolan ACL\u2019leri de\u011fi\u015ftirme gereklili\u011fi vard\u0131r. Bu i\u015flem a\u015fa\u011f\u0131daki komutlar ile yap\u0131l\u0131r.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>netsh http delete urlacl url=http:\/\/+:5985\/wsman\/<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>netsh http add urlacl url=http:\/\/+:5985\/wsman\/ sddl=D:(A;;GX;;;S-1-5-80-569256582-2953403351-2909559716-1301513147-412116970)(A;;GX;;;S-1-5-80-4059739203-877974739-1245631912-527174227-2996563517)<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>netsh http delete urlacl url=https:\/\/+:5986\/wsman\/<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>netsh http add urlacl url=https:\/\/+:5986\/wsman\/ sddl=D:(A;;GX;;;S-1-5-80-569256582-2953403351-2909559716-1301513147-412116970)(A;;GX;;;S-1-5-80-4059739203-877974739-1245631912-527174227-2996563517)<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/4.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/4-1024x317.png\" alt=\"\" class=\"wp-image-146\" width=\"630\" height=\"195\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/4-1024x317.png 1024w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/4-300x93.png 300w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/4-768x238.png 768w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/4-1200x371.png 1200w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/4.png 1403w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Art\u0131k clientlerimiz i\u00e7in bir subscription olu\u015fturabiliriz.<\/p>\n\n\n\n<p>Event Viewer \u00fczerinde sa\u011f k\u0131s\u0131mda bulunan Create Subscription k\u0131sm\u0131na t\u0131kl\u0131yoruz. A\u00e7\u0131lan pencerede Source Computer Initiated k\u0131sm\u0131na t\u0131klad\u0131ktan sonra Select Computer Groups butonuna t\u0131klay\u0131p eklemek istedi\u011fimiz makineleri se\u00e7iyoruz.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/5.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/5-1024x607.png\" alt=\"\" class=\"wp-image-147\" width=\"632\" height=\"374\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/5-1024x607.png 1024w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/5-300x178.png 300w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/5-768x456.png 768w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/5-1200x712.png 1200w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/5.png 1421w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Test ortam\u0131nda tek bir Windows 10 makine ekleyece\u011fim i\u00e7in bu makineyi se\u00e7iyorum.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/6.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/6.png\" alt=\"\" class=\"wp-image-149\" width=\"572\" height=\"483\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/6.png 577w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/6-300x253.png 300w\" sizes=\"(max-width: 572px) 85vw, 572px\" \/><\/a><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Ard\u0131ndan hangi log kategorilerini toplayaca\u011f\u0131m\u0131 belirtmek i\u00e7in Select Events k\u0131sm\u0131n\u0131 se\u00e7iyorum.<br>Ben bu \u00f6rnek i\u00e7in Application, System, Security, Setup, Powershell ve Sysmon\u2019u se\u00e7tim.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/7.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"592\" height=\"575\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/7.png\" alt=\"\" class=\"wp-image-158\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/7.png 592w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/7-300x291.png 300w\" sizes=\"(max-width: 592px) 85vw, 592px\" \/><\/a><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Bu sayfada yapt\u0131\u011f\u0131m\u0131z i\u015flemleri kaydetmeden \u00f6nce Advanced butonuna t\u0131kl\u0131yoruz. Buradaki men\u00fcden loglar\u0131n bize g\u00f6nderilme \u00f6nceli\u011fini optimize edebiliyoruz. Loglar\u0131n g\u00f6nderimine \u00f6ncelik verilmesi i\u00e7in Minimize Latency se\u00e7ene\u011fini se\u00e7iyoruz. \u0130letim zaten kerberos \u00fczerinden yap\u0131ld\u0131\u011f\u0131 i\u00e7in kriptolu ger\u00e7ekle\u015fti\u011finden ekstra bir \u015fifrelemeye gerek duymuyoruz ve bu sebeple protokol\u00fc HTTP olarak b\u0131rak\u0131yoruz.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/8.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"575\" height=\"492\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/8.png\" alt=\"\" class=\"wp-image-159\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/8.png 575w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/8-300x257.png 300w\" sizes=\"(max-width: 575px) 85vw, 575px\" \/><\/a><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>WEF sunucumuz art\u0131k tan\u0131mlad\u0131\u011f\u0131m\u0131z makineden gelen loglar\u0131 almaya haz\u0131r vaziyette.<br>Client taraf\u0131nda yap\u0131lmas\u0131 gerekli ayarlar\u0131 group policy \u00fczerinden yapaca\u011f\u0131z. Bu sebeple domain controller\u2019da oturum a\u00e7\u0131yoruz.<\/p>\n\n\n\n<p>Group policy management console\u2019u a\u00e7t\u0131ktan sonra yeni bir GPO olu\u015fturuyoruz. Bu \u00f6rnek i\u00e7in ad\u0131na WEF-POLICY dedim ve loglar\u0131n\u0131 almak istedi\u011fim makine bu OU alt\u0131nda bulundu\u011fu i\u00e7in CLIENTS isimli OU\u2019ya ba\u011flad\u0131m.<br>Bu policy\u2019yi d\u00fczenleyelim<\/p>\n\n\n\n<p>\u0130lk olarak Client makinelerde Windows Event Forwarder servisinin Event Loglar\u0131 okuyabilmesi i\u00e7in Network Service hesab\u0131n\u0131 Event Log Readers grubuna \u00fcye yap\u0131yoruz. Bunun i\u00e7in <strong>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Restricted Group<\/strong> alt\u0131nda<strong> NT AUTHORITY\\Network Service<\/strong> hesab\u0131n\u0131 <strong>Event Log Readers<\/strong> grubunun \u00fcyesi yap\u0131yoruz.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/10.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/10-1024x811.png\" alt=\"\" class=\"wp-image-160\" width=\"631\" height=\"499\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/10-1024x811.png 1024w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/10-300x238.png 300w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/10-768x608.png 768w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/10.png 1062w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Ard\u0131ndan client makinelerinin restart olmas\u0131 durumunda Windows Remote Management servisinin otomatik ba\u015flamas\u0131n\u0131 sa\u011flamak i\u00e7in <strong>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; System Services &gt; Windows Remote Management<\/strong> k\u0131sm\u0131n\u0131 a\u015fa\u011f\u0131daki foto\u011frafta g\u00f6r\u00fcld\u00fc\u011f\u00fc gibi ayarl\u0131yoruz.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/11.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/11.png\" alt=\"\" class=\"wp-image-162\" width=\"630\" height=\"448\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/11.png 986w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/11-300x214.png 300w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/11-768x547.png 768w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>A\u015fa\u011f\u0131daki ayarlar\u0131 mevcut GPO&#8217;muza s\u0131ras\u0131yla uyguluyoruz.<br><br>Burada collector rol\u00fcndeki makinemize g\u00f6nderilecek EPS miktar\u0131n\u0131 belirtiyoruz. Ben bu \u00f6rnekte <strong>5000 <\/strong>olarak belirledim.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; Windows Components &gt; Event Forwarding &gt;  Configure forwarder resource usage = 5000<\/code><\/pre>\n\n\n\n<p>Burada collector makinemizi belirtiyoruz. Bu \u00f6rnekte makine ad\u0131m\u0131z <strong>SERVER-1.okar.local.<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; Windows Components &gt; Event Forwarding &gt;  Configure target Subscription Manager = Server=http:\/\/SERVER-1.okar.local:5985\/wsman\/SubscriptionManager\/WEC,Refresh=60<\/code><\/pre>\n\n\n\n<p>Bu k\u0131s\u0131mda ilgili gruplar\u0131n log access izinleri i\u00e7in ACL ayarlar\u0131n\u0131 belirtiyoruz.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; Windows Components &gt; Event Log Service &gt; Security &gt; Configure log access &gt; O:BAG:SYD:(A;;0xf0005;;;SY)(A;;0x5;;;BA)(A;;0x1;;;S-1-5-32-573)(A;;0x1;;;S-1-5-20)<\/code><\/pre>\n\n\n\n<p class=\"has-text-align-center\"><br><em>******************************<\/em><\/p>\n\n\n\n<p>Windows 10 makinemizde oturum a\u00e7abiliriz. gpresult ile policy&#8217;nin uygulan\u0131p uygulanmad\u0131\u011f\u0131n\u0131 kontrol edebiliriz.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/12.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/12.png\" alt=\"\" class=\"wp-image-164\" width=\"628\" height=\"478\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/12.png 711w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/12-300x229.png 300w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/figure>\n\n\n\n<p>Applied Group Policy Object alt\u0131nda bir \u00f6nceki ad\u0131mda DC \u00fczerinde olu\u015fturdu\u011fumuz WEF-POLICY objemizin hen\u00fcz okunmad\u0131\u011f\u0131n\u0131 g\u00f6r\u00fcyoruz.<br>Bu y\u00fczden gpupdate \/force ile yeni policy&#8217;mizi \u00e7ekiyoruz.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/13.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/13.png\" alt=\"\" class=\"wp-image-165\" width=\"630\" height=\"638\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/13.png 664w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/13-296x300.png 296w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/figure>\n\n\n\n<p>WEF-POLICY objemizin client taraf\u0131ndan \u00e7ekildi\u011fini g\u00f6r\u00fcyoruz.<br>\u015eimdi WEF sunucuda bulunan subscriptionlar\u0131 kontol edelim. <br>Event Viewer k\u0131sm\u0131nda bulunan Subscriptions i\u00e7inde Source Computers k\u0131sm\u0131nda 1 rakam\u0131n\u0131 g\u00f6r\u00fcyoruz. Bu \u015fu anda bize aktif olarak log g\u00f6nderen 1 maknenin oldu\u011funu g\u00f6steriyor.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/14.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/14-1024x391.png\" alt=\"\" class=\"wp-image-166\" width=\"629\" height=\"240\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/14-1024x391.png 1024w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/14-300x115.png 300w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/14-768x293.png 768w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/14-1200x459.png 1200w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/14.png 1421w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/figure>\n\n\n\n<p><br>Fowrarded Events sekmesini kontrol edersek bu k\u0131sm\u0131n CLIENT-1 makinesinden gelen loglarla dolmaya ba\u015flad\u0131\u011f\u0131n\u0131 g\u00f6rebiliriz.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/15.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/15-1024x608.png\" alt=\"\" class=\"wp-image-168\" width=\"629\" height=\"373\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/15-1024x608.png 1024w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/15-300x178.png 300w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/15-768x456.png 768w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/15-1200x713.png 1200w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/15.png 1422w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/figure>\n\n\n\n<p>\u015eimdi bu makinenin loglar\u0131n\u0131 Logsign Siem&#8217;imize y\u00f6nlendirelim.<br>Bu i\u015flem i\u00e7in NXLog yap\u0131land\u0131rma dosyas\u0131na a\u015fa\u011f\u0131daki eklemeyi yapmak gerekiyor. <em>(NXLog kurulum ve yap\u0131land\u0131rmas\u0131 bu yaz\u0131n\u0131n kapsam\u0131 d\u0131\u015f\u0131nda bulundu\u011fu i\u00e7in ayr\u0131nt\u0131s\u0131na girilmeyecektir).<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/16.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"506\" height=\"74\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/16.png\" alt=\"\" class=\"wp-image-169\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/16.png 506w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/16-300x44.png 300w\" sizes=\"(max-width: 506px) 85vw, 506px\" \/><\/a><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;Select Path=\"ForwardedEvents\"&gt;*&lt;\/Select&gt;\\<\/code><\/pre>\n\n\n\n<p>Yukar\u0131da bulunan sat\u0131r varolan yap\u0131land\u0131rmaya eklendikten sonra art\u0131k Forwarded Events alt\u0131nda bulunan loglar da siem&#8217;e g\u00f6nderilmeye ba\u015flanacakt\u0131r.<br>\u015eimdi Logsign taraf\u0131nda EventSource.HostName filtresini kullanarak CLIENT-1.okar.local&#8217;den gelen loglar\u0131 filtreleyelim.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/17.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/17-1024x358.png\" alt=\"\" class=\"wp-image-171\" width=\"630\" height=\"220\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/17-1024x358.png 1024w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/17-300x105.png 300w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/17-768x269.png 768w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/17-1536x537.png 1536w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/17-1200x420.png 1200w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/17.png 1673w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/figure>\n\n\n\n<p>Foto\u011frafta g\u00f6r\u00fcld\u00fc\u011f\u00fc gibi CLIENT-1&#8217;in loglar\u0131 WEF makinemiz \u00fczerinden siem&#8217;imize akmaya ba\u015flad\u0131.<br>CLIENT-1 \u00fczerinde Test User kullan\u0131c\u0131s\u0131 ile birka\u00e7 hatal\u0131 login hareketi yap\u0131p inceleyelim.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/18.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/18.png\" alt=\"\" class=\"wp-image-172\" width=\"631\" height=\"462\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/18.png 981w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/18-300x220.png 300w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/18-768x562.png 768w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>A\u015fa\u011f\u0131da CLIENT-1 \u00fczerinde yapt\u0131\u011f\u0131m\u0131z hatal\u0131 login hareketlerini g\u00f6rebiliriz.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/19.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/19-1024x297.png\" alt=\"\" class=\"wp-image-173\" width=\"629\" height=\"182\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/19-1024x297.png 1024w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/19-300x87.png 300w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/19-768x223.png 768w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/19-1536x445.png 1536w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/19-1200x348.png 1200w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/19.png 1676w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Manuel olarak bir makine daha ekleyelim ve WEF \u00fczerindeki Event Viewer&#8217;\u0131n nas\u0131l davrand\u0131\u011f\u0131n\u0131 g\u00f6zleyelim.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/21.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/21.png\" alt=\"\" class=\"wp-image-175\" width=\"535\" height=\"439\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/21.png 531w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/21-300x246.png 300w\" sizes=\"(max-width: 535px) 85vw, 535px\" \/><\/a><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>CLIENT-2 eklendikten sonra WEF sunucuda Event Viewer alt\u0131nda bulunan Computers kolununda art\u0131k CLIENT-1&#8217;in yan\u0131nda CLIENT-2&#8217;yi de g\u00f6rmeye ba\u015fl\u0131yoruz. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/22.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/22-1024x392.png\" alt=\"\" class=\"wp-image-176\" width=\"631\" height=\"241\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/22-1024x392.png 1024w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/22-300x115.png 300w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/22-768x294.png 768w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/22.png 1108w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Siem taraf\u0131ndan da kontrol ederek log ak\u0131\u015f\u0131n\u0131n CLIENT-2 i\u00e7in de varoldu\u011funu g\u00f6rebiliyoruz.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/23.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/23-1024x330.png\" alt=\"\" class=\"wp-image-177\" width=\"631\" height=\"203\" srcset=\"https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/23-1024x330.png 1024w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/23-300x97.png 300w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/23-768x247.png 768w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/23-1536x495.png 1536w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/23-1200x386.png 1200w, https:\/\/canokar.com\/wp-content\/uploads\/2023\/05\/23.png 1668w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Merhaba bu yaz\u0131m\u0131zda test ortam\u0131m\u0131zda bulunan bir Windows 10 client\u2019\u0131n event loglar\u0131n\u0131 Microsoft\u2019un WEF yap\u0131land\u0131rmas\u0131n\u0131 kullanarak \u00f6nce WEF sunucumuza g\u00f6nderece\u011fiz ard\u0131ndan WEF sunucumuz \u00fczerinden NXLog ile Logsign Siem sunucumuza g\u00f6nderece\u011fiz. WEF bize ne sa\u011flaycak?&#8211; WEF ile yap\u0131m\u0131zda bulunan makinelerin loglar\u0131n\u0131 bu makinelere ajan kurma gereksinimi duymadan bu makinelerin loglar\u0131n\u0131 sadece bir group policy arac\u0131l\u0131\u011f\u0131 ile &hellip; <a href=\"https:\/\/canokar.com\/?p=132\" class=\"more-link\">Okumaya devam et<span class=\"screen-reader-text\"> &#8220;Microsoft WEF yap\u0131land\u0131rmas\u0131 ve Logsign Siem ile entegrasyonu&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":182,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"_ti_tpc_template_sync":false,"_ti_tpc_template_id":""},"categories":[11],"tags":[8,9,10,5,6,7],"_links":{"self":[{"href":"https:\/\/canokar.com\/index.php?rest_route=\/wp\/v2\/posts\/132"}],"collection":[{"href":"https:\/\/canokar.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/canokar.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/canokar.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/canokar.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=132"}],"version-history":[{"count":29,"href":"https:\/\/canokar.com\/index.php?rest_route=\/wp\/v2\/posts\/132\/revisions"}],"predecessor-version":[{"id":192,"href":"https:\/\/canokar.com\/index.php?rest_route=\/wp\/v2\/posts\/132\/revisions\/192"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/canokar.com\/index.php?rest_route=\/wp\/v2\/media\/182"}],"wp:attachment":[{"href":"https:\/\/canokar.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=132"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/canokar.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=132"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/canokar.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=132"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}