Tuning WinCollect
WinCollect comes with many configurable parameters. It has different tuning profiles, polling intervals, and a number of channels. All this is made available to the user to choose the correct option for the amount of data that needs to be collected either from the Windows machine or remotely pulled from other Windows machines.
There are three important parameters for the tuning of WinCollect:
- Event Rate Tuning Profile: We know that Windows machines could be our endpoint desktops or could be servers. On servers, there could also be different types of servers. Some could be email servers, web servers, or even DNS servers.
Depending on the number of events generated per second by a Windows machine, the categorization is as follows:
- Windows Endpoint Default: These are the endpoint desktop machines that produce the lowest number of events per second.
- Typical Server: These are typical servers that generate more events than endpoints. These...