Windows Event Collector (WEC) - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR Prevent Administrator Guide

Product
Cortex XDR
License
Prevent
Creation date
2024-07-16
Last date published
2024-12-04
Category
Administrator Guide
Retire_Doc
Retiring
Link_to_new_Doc
/r/Cortex-XDR/Cortex-XDR-Documentation

The WEC runs on the Broker VM in Cortex XDR/Cortex XSIAM collecting event logs from Windows Servers, including Domain Controllers (DCs). The WEC can be deployed in multiple setups, and can be connected directly to multiple event generators (DCs or Windows Servers) or routed using one or more WECs. Behind each WEC there may be multiple generating sources.