Connectors of the wec type are used for getting data using Windows Event Forwarding (WEF) and Windows Event Collector (WEC), or local operating system logs of a Windows host when working with Windows agents. Settings for a connector of the wec type are described in the following tables.
Basic settings tab
| Setting | Description | 
|---|---|
| Name | Unique name of the resource. The maximum length of the name is 128 Unicode characters. Required setting. | 
| Tenant | The name of the tenant that owns the resource. Required setting. | 
| Type | Connector type: wec. Required setting. | 
| Tags | Tags for resource search. Optional setting. | 
| URL | URL of the collector that you created to receive data using Windows Event Collector, for example,  When a collector is created, an agent is automatically created that will get data on the remote device and forward it to the collector service. If you know which server the collector service will be installed on, the URL is known in advance. You can enter the URL of the collector in the URL field after completing the Installation Wizard. To do so, you first need to copy the URL of the collector in the Resources → Active services section. Required setting. | 
| Windows logs | The names of the Windows logs that you want to get. By default, this drop-down list includes only preconfigured logs, but you can add custom log to the list. To do so, enter the names of the custom logs in the Windows logs field, then press ENTER. KUMA service and resource configurations may require additional changes in order to process custom logs correctly. Preconfigured logs: 
 If the name of at least one log is specified incorrectly, the agent using the connector does not receive events from any log, even if the names of other logs are correct. Required setting. | 
| Description | Description of the resource. The maximum length of the description is 4000 Unicode characters. | 
Advanced settings tab
| Setting | Description | 
|---|---|
| Debug | The switch enables resource logging. The toggle switch is turned off by default. | 
| Character encoding | Character encoding. The default is UTF-8. | 
| TLS mode | TLS encryption mode. When using TLS encryption, you cannot specify an IP address in the URL field on the Basic settings. Available values: 
 | 
| Compression | Drop-down list for configuring Snappy compression: 
 | 
If you edit a connector of this type, the TLS mode and Compression settings are visible and available on the connector resource as well as the collector. If you are using a connector of this type on a collector, the values of TLS mode and Compression settings are sent to the destination of automatically created agents.
To start the KUMA agent on the remote device, you must use a service account with the “Log on as a service” permissions. To receive events from the operating system log, the service user account must also have Event Log Readers permissions.
You can create one user account with “Log on as a service” and “Event Log Readers” permissions, and then use a group policy to extend the rights of this account to read the logs to all servers and workstations in the domain.
We recommend that you disable interactive logon for the service account.
Page top