skip to content
 
 

What is a log collection agent?

A log collection agent is software installed on a host (or on a nearby machine that can reach it) that captures logs locally, buffers them, and ships them to a central platform in real time. Because the agent lives on the network segment where the logs originate, it doesn't need the log collector to have inbound access. The agent initiates the connection outbound, over a single controllable port, in an environment where opening WMI or RPC across the firewall is not feasible.

In EventLog Analyzer, log collection using an agent is optional. By default, the solution deploys agentless log collection. If your enterprise IT security policy does not allow opening WMI ports, or when events need to traverse WAN links reliably, an agent-based path exists as an alternative to agentless collection.

Agent-based log collection

EventLog Analyzer ships a purpose-built log collection agent which runs alongside agentless collection rather than replacing it where both modes feed the same pipeline under one console. In agent-based collection, the logs from various sources are automatically fetched by the agent and transmitted to a central server.

Agent configuration and setup

Getting the agent running is a five-step operation from the admin console. There's no separate installer to run on the endpoint—EventLog Analyzer pushes the install remotely.

  1. In the EventLog Analyzer console, go to Settings > Log Source Configuration> Add Agent.
  2. Select the target device(s) from the discovered device list.
  3. Assign credentials with local admin rights on the target.
  4. Define the log sources to collect—Windows audit logs (Security,System, Application, or custom), file paths for text logs, and syslog listeners.
  5. Activate collection. The agent begins forwarding within seconds.

One agent handles up to roughly 25 Windows devices within its LAN. Assignment is flexible: A device can be handled by the agent directly, or the server can collect from it agentless, or it can be reassigned from one agent to another as the environment changes.

The agent configuration console in EventLog Analyzer
Figure 1: The agent configuration console in EventLog Analyzer.

Agent-based log collection in Windows

Once installed, the agent reads events directly from the Windows event log service on each assigned host. It uses the native Windows Event Log API rather than WMI, which is the main reason it works where agentless doesn't. No WMI ports need to be opened on firewalls between the source and collector. The agent forwards events to the EventLog Analyzer server continuously in real time. Transport is via TCP, initiated outbound from the agent.

Refer to the event log collection page for more details on collecting Windows logs in EventLog Analyzer.

Agent-based log collection in Linux

When it comes to Linux or Unix hosts, the agent auto-detects the local syslog daemon and configures forwarding to the EventLog Analyzer server without hand-editing configuration files. The syslog port and protocol are configurable per device, so the agent can be pointed at whatever port the local network policy allows.

The Windows and Linux agent  administration console in EventLog Analyzer
Figure 2: The Windows and Linux agent administration console in EventLog Analyzer.

Agent-based vs. agentless log collection

Neither mode is universally better. Both are supported for a reason. The right question is: Which one applies to this specific device, on this specific network segment, under this specific policy?

Use the agent when: the device is behind a firewall that doesn't allow WMI or RPC inbound; the connection to the collector is a WAN link with latency or packet loss; enterprise policy prohibits opening WMI ports; the device runs on a network segment (DMZ, isolated VPC) with strict outbound rules; or log volume from a source is high enough that endpoint-side buffering matters.

Use agentless when: the device is on the same LAN as the collector; WMI or RPC ports are open; the endpoint is locked down for a reason (regulated appliance, third-party managed system) and adding software isn't permitted; or the operations team wants zero endpoint-side maintenance.

Mixing modes is normal. A typical deployment runs agentless for the office LAN and agent-based for branch offices, DMZ hosts, and cloud workloads.

 

Frequently asked questions

A log collection agent is a software component installed on a host machine that captures logs locally and forwards them to a central log management platform in real time. Agents are what enable log collection across WAN links, through firewalls, and in segmented networks where agentless approaches can't reach.

Agent-based collection puts a piece of software on the source host; the host itself does the forwarding. Agentless collection puts nothing on the host—the central server reaches out and pulls the logs over standard protocols like WMI or SSH. Agents are for network-constrained environments; agentless is for well-connected LANs. EventLog Analyzer supports both simultaneously.

Windows servers and workstations for event log collection; Linux and Unix hosts for syslog and Journald; and any device or application that writes to a local file the agent can read. Network devices (routers, switches, and firewalls) that emit syslog natively are usually collected without an agent by forwarding syslog directly to the server.

Yes—that's the primary use case. The agent initiates outbound connections to the collector on a single configurable port, which is significantly easier to permit through a firewall than the multiple ports WMI or RPC would require inbound. For WAN links, the agent buffers locally, so brief network interruptions don't drop events.

EventLog Analyzer Trusted By

Los Alamos National Bank Michigan State University
Panasonic Comcast
Oklahoma State University IBM
Accenture Bank of America
Infosys
Ernst Young

Customer Speaks

  • Credit Union of Denver has been using EventLog Analyzer for more than four years for our internal user activity monitoring. EventLog Analyzer provides great value as a network forensic tool and for regulatory due diligence. This product can rapidly be scaled to meet our dynamic business needs.
    Benjamin Shumaker
    Vice President of IT / ISO
    Credit Union of Denver
  • The best thing, I like about the application, is the well structured GUI and the automated reports. This is a great help for network engineers to monitor all the devices in a single dashboard. The canned reports are a clever piece of work.
    Joseph Graziano, MCSE CCA VCP
    Senior Network Engineer
    Citadel
  • EventLog Analyzer has been a good event log reporting and alerting solution for our information technology needs. It minimizes the amount of time we spent on filtering through event logs and provides almost near real-time notification of administratively defined alerts.
    Joseph E. Veretto
    Operations Review Specialist
    Office of Information System
    Florida Department of Transportation
  • Windows Event logs and device Syslogs are a real time synopsis of what is happening on a computer or network. EventLog Analyzer is an economical, functional and easy-to-utilize tool that allows me to know what is going on in the network by pushing alerts and reports, both in real time and scheduled. It is a premium software Intrusion Detection System application.
    Jim Lloyd
    Information Systems Manager
    First Mountain Bank

Awards and Recognitions

  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
A Single Pane of Glass for Comprehensive Log Management