- On-premises (VMware or Hyper-V Sensors)
-
Amazon Web Service (AWS), where the Windows source machines are deployed within one of the following configurations:
- The Windows source machines, the NXLog agent server, and USM Anywhere Sensor are located in the same Amazon Virtual Private Cloud (VPC).
- The Windows source machines, the NXLog agent server, and USM Anywhere Sensor are not located in the same Amazon VPC, but you have VPC peering configured to allow the NXLog server to communicate with the sensor using UDP port 514.
- Azure, where the Windows source machines, the NXLog agent server, and USM Anywhere Sensor are located in the same virtual network.
Important: Because it does not require that you set up log forwarding on each source, the easiest and most straightforward method for Windows log collection in an Azure environment is to collect the Windows security events from the Azure storage account. However, if you need the additional logs forwarded by NXLog, you can use the following information to configure Windows log collection for this environment.