A SIEM administrator is troubleshooting why Windows event logs forwarded from a domain controller are not being parsed correctly. The logs are sent using the Windows Event Forwarding (WEF) subscription, but the SIEM shows raw XML instead of normalized fields. The administrator confirms that the WEF subscription is active and events are arriving. Which action should the administrator take to ensure proper parsing?
Trap 1: Install a SIEM agent on the domain controller to read the event…
Installing a SIEM agent could bypass WEF and send logs in a format the SIEM understands, but it introduces additional management overhead and may not be necessary. The scenario specifies that WEF is already active and events are arriving; the problem is parsing, not collection. Adding an agent does not address the root cause and could create duplicate events if WEF remains enabled, complicating the SIEM data ingestion.
Trap 2: Configure the SIEM to use the Windows Event Log collector with the…
While using a Windows Event Log collector can help, the issue is that the logs are arriving as raw XML. Simply enabling XML parsing in the collector may not map the fields to the SIEM's schema. The collector must be configured with the appropriate event channel and a parsing ruleset that extracts fields from the XML structure. Without the correct parser, the SIEM will still store raw XML, so this action alone does not resolve the normalization problem.
Trap 3: Modify the WEF subscription to forward events in JSON format…
Windows Event Forwarding natively forwards events in XML format; there is no built-in option to change the output to JSON. While some third-party tools can convert XML to JSON, WEF itself does not support this. Attempting to modify the subscription to output JSON is not feasible and would not resolve the parsing issue. The correct approach is to adapt the SIEM's parser to the XML format.
- A
Install a SIEM agent on the domain controller to read the event logs directly and forward them in a normalized format.
Why it fails: Installing a SIEM agent could bypass WEF and send logs in a format the SIEM understands, but it introduces additional management overhead and may not be necessary. The scenario specifies that WEF is already active and events are arriving; the problem is parsing, not collection. Adding an agent does not address the root cause and could create duplicate events if WEF remains enabled, complicating the SIEM data ingestion.
- B
Configure the SIEM to use the Windows Event Log collector with the correct channel names and enable XML parsing.
Why it fails: While using a Windows Event Log collector can help, the issue is that the logs are arriving as raw XML. Simply enabling XML parsing in the collector may not map the fields to the SIEM's schema. The collector must be configured with the appropriate event channel and a parsing ruleset that extracts fields from the XML structure. Without the correct parser, the SIEM will still store raw XML, so this action alone does not resolve the normalization problem.
- C
Modify the WEF subscription to forward events in JSON format instead of XML.
Why it fails: Windows Event Forwarding natively forwards events in XML format; there is no built-in option to change the output to JSON. While some third-party tools can convert XML to JSON, WEF itself does not support this. Attempting to modify the subscription to output JSON is not feasible and would not resolve the parsing issue. The correct approach is to adapt the SIEM's parser to the XML format.
- D
Create a custom parser in the SIEM that extracts fields from the XML structure of the WEF events.
When WEF forwards events, they are encapsulated in XML. If the SIEM's default Windows parser expects a different format (e.g., EVTX or JSON), it will fail to extract fields, resulting in raw XML. Creating a custom parser that understands the WEF XML schema and maps fields like EventID, Computer, and SubjectUserName to the SIEM's normalized schema will enable proper parsing and correlation.