...
We are providing you with the steps to integrate your Watchguard Firewall event collection at windows collector computer with Seceon SIEM so One can have Comprehensive visibility and Proactive Threat Detection in your Environment. There will be a log transfer between your firewall to APE(Analytics and Policy Engine) via CCE (Collection and Control Engine ). In this document, we are guiding you through the steps for Log and Netflows forwarding.
Steps of configuration-
On the collector computer, type the following at an elevated command on command prompt:
1. PS C:\Users\Administrator>wecutil wecutil qc
Create Now create a New Subscription
2 On the collector computer in search box, run Event Viewer as an administrator.
3 Click Subscriptions in the console tree.which is situated in the left side
4 Start Windows Collector Service
If the Windows Event Collector service is not started, you will be prompted to confirm that you want to start it. This service must be started to create subscriptions and collect events. You must be a member of the Administrators group to start this service.
5 On the Actions actions menu, click Create Subscriptionin right side click on the create subscription.
6 In the Subscription Name box, type a name for the subscription
7 In the Description box, enter an optional description.
8 In the Destination Log box, select the log file with help of dropdown where collected events are to be stored. Please make sure that the collected events are stored in the "System" log.
9 Click Add and select the
9 now click on select computers from which events are to be collected.
Now put the computer name one by one
10 After adding a computer, you can test connectivity between it and the local computer by selecting the computer and clicking Test.
...