Summary
WinCollect agents make it easier for QRadar admins to collect required data from Windows machines. Using other protocols such as MSRPC may present certain challenges, which are then addressed using WinCollect agents. Therefore, to collect events from Windows machines, the WinCollect agent is the recommended solution. In this chapter, we have seen different types of WinCollect agents and understood the different scenarios to use them in. In addition, we have dug deep into tuning the WinCollect agent for optimal performance.
In the next chapter, which will be the last chapter of the book, we will cover QRadar troubleshooting, frequently asked questions about QRadar, and the next-generation look of QRadar.