I follwed this link: https://www.manageengine.com/products/active-directory-audit/help/getting-started/domain-controllers-advanced-audit-policy.html
Modified in "Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> Audit Policies" Executed "gpupdate /force" on all my domains controllers. Now I have the logs in Ossec Server. Thank You Enrico Il giorno mercoledì 20 giugno 2018 18:06:27 UTC+2, e.fanti e.fanti ha scritto: > > Hello to all. > Almost every day the following thing happens. > I have 2 agents installed on two windows 2008 servers. > The agent is connected to the Wazuh Manager, but windows events are not > sent to the Wazuh server. > The events are present on the Windows server. > > > The restart of the windows agent does not send the events > > > On the Wazuh server I have only the messages related to the restart of the > agent on the windows server > > Thank you > > Enrico > -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.