Currently, I have the Sentinel Agent installed on the windows machines. Would the best solution be to install edge on the all the window machines and send to stream or forward all the logs to a central windows machine and then send from there with Edge?
Solved
Ideal way to send Windows logs to Sentinel?
Best answer by xpac xpac
I' put Edge on each box, and collect the events from there. Forwarding to a central box is something I'd avoid, to have less of a SPOF.
If you do it, I'd use Stream for the central box instead of Edge.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
