GSEC Log Management and SIEM Practice Question
A SIEM administrator is troubleshooting why Windows event logs forwarded from a domain controller are not being parsed correctly. The logs are sent using the Windows Event Forwarding (WEF) subscription, but the SIEM shows raw XML instead of normalized fields. The administrator confirms that the WEF subscription is active and events are arriving. Which action should the administrator take to ensure proper parsing?
⚠ Common exam trap
The trap here is assuming that enabling generic XML parsing will automatically map fields correctly, when a custom parser tailored to the WEF schema is needed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom parser in the SIEM that extracts fields from the XML structure of the WEF events.
WEF forwards events in XML format. If the SIEM's collector is not configured to parse that XML, it stores raw XML and fields are not normalized. The administrator should create a custom parser that extracts relevant fields from the WEF XML schema and maps them to the SIEM's data model. Other options either do not address the parsing issue or are technically infeasible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Install a SIEM agent on the domain controller to read the event logs directly and forward them in a normalized format.
Why it's wrong here
Installing a SIEM agent could bypass WEF and send logs in a format the SIEM understands, but it introduces additional management overhead and may not be necessary. The scenario specifies that WEF is already active and events are arriving; the problem is parsing, not collection. Adding an agent does not address the root cause and could create duplicate events if WEF remains enabled, complicating the SIEM data ingestion.
- ✗
Configure the SIEM to use the Windows Event Log collector with the correct channel names and enable XML parsing.
Why it's wrong here
While using a Windows Event Log collector can help, the issue is that the logs are arriving as raw XML. Simply enabling XML parsing in the collector may not map the fields to the SIEM's schema. The collector must be configured with the appropriate event channel and a parsing ruleset that extracts fields from the XML structure. Without the correct parser, the SIEM will still store raw XML, so this action alone does not resolve the normalization problem.
- ✗
Modify the WEF subscription to forward events in JSON format instead of XML.
Why it's wrong here
Windows Event Forwarding natively forwards events in XML format; there is no built-in option to change the output to JSON. While some third-party tools can convert XML to JSON, WEF itself does not support this. Attempting to modify the subscription to output JSON is not feasible and would not resolve the parsing issue. The correct approach is to adapt the SIEM's parser to the XML format.
- ✓
Create a custom parser in the SIEM that extracts fields from the XML structure of the WEF events.
Why this is correct
When WEF forwards events, they are encapsulated in XML. If the SIEM's default Windows parser expects a different format (e.g., EVTX or JSON), it will fail to extract fields, resulting in raw XML. Creating a custom parser that understands the WEF XML schema and maps fields like EventID, Computer, and SubjectUserName to the SIEM's normalized schema will enable proper parsing and correlation.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.