Windows Event Collector
| Typically Used By | Windows-centric organizations; Active Directory environments |
| Description | A Windows-specific collector that gathers event logs from Windows systems with native support for Windows authentication and event formats. |
| Official Vendor Documentation | https://learn.microsoft.com/en-us/windows/win32/wec/windows-event-collector |
| Setup Difficulty | 3 (Moderate) |
| Useful for | IT Ops , SecOps |
| Primary Use Case | Centralized Windows event logs |
| Scenarios not Recommended | Non-Windows environments; Organizations requiring cross-platform collection |
| Data Volume Handling | Medium |
| Authentication Method | Windows authentication |
| Fault Tolerance | Medium |
| Additional Tools Required | None |
Windows Event Collector (WEC) is a Windows service that collects events from Windows Event Logs on remote computers and forwards them to a central collector (in this case, Falcon LogScale Collector). WEC supports various event collection methods, including source computer initiated and collector initiated subscriptions. By integrating WEC with Falcon LogScale Collector, organizations can centralize Windows event logging, automate incident response, and correlate Windows events with other log data for comprehensive threat detection and compliance reporting.
Windows Event Collector ingest flowThe following diagram shows how Windows Event Collector log data flows through Log Collector's ingestion pipeline, highlighting specific parser types applied to the log data before data is compressed, stored in the repository, and indexed for searching: