Enable sharing Windows security logs from an on-premises Active Directory server with Risk Insights.
Configuring log forwarding allows Active Directory to share Windows security logs (such as object access events, logon/logoff events, system events, and account management events) with Risk Insights through a configured Service Gateway.
Before you begin, you must have at least one Service Gateway virtual appliance deployed and configured. For more information, see Service Gateway Management.
Log Forwarding requires a Service Gateway API key. To obtain the key, go to Workflow and Automation > Service Gateway Management and click Manage API Key.
Changing the API key invalidates previously generated API keys.
A tooltip with information about the installation package appears.
If SSL certificates are imported, the certificates must be the same as the ones used in Service Gateways
Any configuration changes on the Trend Vision One console take 5 minutes to reflect on the log forwarding agent.
If the log forwarding agent user interface is open, the automatic updates process stops.