Open thomasxm opened 1 year ago
Hello @thomasxmeng,
No, it does not send the logs to a dedicated log channel. However, you can find the output of its detections inside WHIDS installation directory C:\Program Files\Whids\
. If you didn't change the setting, the logs matching your rules is configured in setting:
# Forwarder's logging configuration
[forwarder.logging]
# Directory used to store logs
dir = "C:\\Program Files\\Whids\\Logs\\Alerts"
Does Whids have a separate channel or place to store events and logs? Like Sysmon is stored under Application and Services/ Windows / Sysmon / Operational. Do we have a place where Whids store all its logs matched its rules?