Unable to see any login or failure event from windows hosts

Hi Folks,

I have setup elastic SIEM 7.15 with fleet and integrations with elastic-agent and windows.
I enrolled windows server in fleet and then I generated few failure events. However those are not being reflected on SIEM App.

Is anything else that I need to do in elastic agent configuration or windows configuration?

Hi Blason,

Couple of questions:

  1. Does you agent show up in the fleet overview?
  2. Do you see any events comin in at all from the host?
  3. What do you mean by "No events reflected in SIEM app"? As in where do you expect them to show?

Regards
Stijn

Hey,

Thanks for the reply- it automatically started appearing the events after sometime.