Helix Enterprise maintains dozens of rules that rely on specific event IDs generated by Windows logs. To get the most out of Helix Enterprise it is important for it to receive logs that could generate meaningful alerts.
Monitoring Windows event logs is an important task for any organization concerned with information security. Logging is commonly underused in many networks with Windows systems. This is sometimes the case because there can be so much information provided by these logs, that it is not always clear to the security practitioner what the important logs are.
Note
Windows has several different types of logs that should be monitored, but they are not all enabled by default.
The best way to check which types of logging are enabled is to perform searches in Helix Enterprise for the specific log types. For more information, see Search functions. Enabling the logging is based on your environment and thus unique. Contact your Helix Enterprise deployment contact for support.
Event logs generating alerts
Helix Enterprise generates alerts when certain factors, including the generation of specific event IDs, are observed in the logs provided. This section contains a list of event IDs that can result in the generation of alerts in Helix Enterprise. This can assist you in determining which Windows logs can result in alerts being generated, and for determining the most efficient ways to generate alerts. The event IDs are grouped in tables according to the appropriate event log that contains them.
Along with the event log and event ID, the event source or category is shown, as well as the number of times it currently appears in a rule. This information should provide guidance as to what could be useful information to provide for Helix Enterprise .
It is important for a system administrator to ensure that logs are enabled on relevant systems. Ideally, all of the logs referenced here would be sent to your Helix Enterprise instance. The tables that follow contain a field heading called, “# of Occurrences in Rules”. This field tells you how frequently a particular event ID appears in a Trellix rule. It is reasonable to then infer that the more times an event ID is found in a rule, the more important it probably is to make sure that the log generating that event is being sent to Helix Enterprise.