Logmanager documentation
Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Back to homepage

Microsoft Windows Firewall

Microsoft Windows Event Sender (WES) (Deprecated) must be running if you want to use this setup procedure.

Use the following steps to set up the log message sending from Windows Firewall to the Logmanager:

Configuring Windows Firewall

  1. Run firewall configuration console with command wf.msc.

    Running configuration

    Running configuration

  2. On the right-hand side select Properties.

    Dashboard

    Dashboard

  3. On the Domain Profile tab, click Customize for Logging.

    Profiles

    Profiles

    • Create a copy of the log file path to the clipboard for future use.
    • Select yes on Log dropped packets.
    • Select yes on Log successful connections.
    • To save this configuration, click OK.
    Customizing logging

    Customizing logging

  4. Repeat the previous steps for Private Profile and Public Profile tabs.

Configuring Logmanager

This procedure demonstrates the GUI configuration for all available messages.

  1. Configure the Logmanager to watch the log files on Windows Server with Windows Firewall. Follow the Chapter Windows.

  2. We find computer with Windows Firewall and we need to set following properties on Editing client station page:

    • Set log type to value text
    • Paste the log file path from your clipboard into textbox log source
    Editing agent

    Editing agent

WES agent starts sending Windows Firewall messages to the Logmanager.