Configure WMI Plugins

Applies to Product: USM Appliance™ AlienVault OSSIM®

Windows Management Instrumentation (WMI) plugins collect Microsoft Windows events and data remotely. These plugins collect the information without an agent, using the Windows Management Instrumentation Command Line (WMIC) .

Note: Currently, WMIC does not support samba4/NTLMv2. Nor does WMIC work on more recent Windows versions, like Windows Server 2012 or later, because these versions authenticate with NLTMv2 only by default.

To use a WMI plugin with a Windows host that uses NTLMv2, you must manually enable NTLMv1 authentication. For information about this, see the Microsoft Support web pages.

The following sections of a WMI plugin are essential.

[start_cmd]

[cmd]

You use [start_cmd] and [cmd] to return the last WMI Application event, and start reading from that event.

Additional Configuration Required Before You Enable an WMI Plugin

You need to perform the following additional configuration before you can use the WMI plugins.

You can now enable the WMI plugin. See Enable Plugins on Assets.