← All use cases

Windows Event Log Monitoring

The LimaCharlie sensor ingests Windows Event Logs directly and in real time, with no collectors or forwarding infrastructure to build. WEL data arrives as structured JSON, gets indexed against common indicators of compromise, and runs through the same detection engine as everything else.

How it runs on LimaCharlie
01

Collect

Sensors stream WEL data as events occur. There is no forwarder tier to deploy, patch, or scale.

02

Detect

Because events arrive as JSON, writing custom detection rules against specific Windows events is the same exercise as writing any other rule. IOC indexing runs automatically on ingest.

03

Import history

Pull historical event logs from disk into the platform, so an investigation can reach back before the sensor was installed.

04

Respond

Detections on WEL data trigger the full range of response actions on the same endpoint, from process kills to network isolation.

EDRThreat hunting
DOCSWindows Event Log collection tutorialDOCSDetection on alternate targets

Deploy your first sensor on the free community tier, or walk through it with a solutions engineer.

Start freeBook a demo