Renew WEC Certificates
Renewing your WEC certificates in Cortex XDR includes
renewing your Windows Event Forwarding (WEF) client certificate
and your WEC server certificate.
Renewing
your WEC certificates in
Cortex
XDR
includes renewing your Windows Event Forwarding
(WEF) client certificate and your WEC server certificate. You must
install the WEF certificate on every Windows server, whether a Domain
Controller (DC) or not, for the WEFs that are supposed to forward
logs to the Windows Event Collector applet on the broker VM.Cortex
XDR
displays a notification
for any tenant with an active WEC applet containing a Certificate
Authority (CA) certificate that expires in less than 90 days. You
will see these notifications in the following places until the WEC
certificates are replaced.After you receive a notification
for renewing your WEC CA certificate, we recommend that you do not
add any new WEF clients until the WEC certification renewal process
is complete. Events from these WEF clients that are added afterwards
will not be collected by the server until the WEC certificates are renewed.
- In theBroker VMspage, the health status of the Windows Event Collector applet is yellow. When your mouse hovers over the health status, a warning message is displayed indicating thatYour Windows Event Collector server certificate expires in X days.
- Until you renew your broker VM WEC server certificate, a warning message is displayed in theWindows Event Forwarder Configurationswindow.
- A new notification entitledWEC Certificate Authority Expirationis displayed in the notification area until the certificates are renewed.
In
addition,
Cortex
XDR
manages
the renewal of your WEC certificates by implementing the following
time limits.- The WEC CA certificate is increased for an extended period of time for a maximum of 20 years.
- The broker VM applet includes an automatic renewal mechanism for a WEC server certificate, which has a lifespan of 12 months.
- The WEC client certificate after the renewal is issued with a lifespan of 5 years.
To renew your WEC certificates:
- Renew your WEF client certificate inCortexXDR.
- InCortexXDR, select, and locate your broker VM.SettingsConfigurationsData BrokerBroker VMs
- Right-click and select.Windows Event CollectorConfigure Forwarder
- In theWindows Event Forwarder Configurationwindow:
(copy) the
Subscription Manage URL. This will be used when you configure the subscription manager in the GPO (Global Policy Object) on your domain controller.- Define Client Certificate Export Passwordused to secure the downloaded WEF certificate used to establish the connection between your DC/WEF and the WEC. You will need this password when the certificate is imported to the events forwarder.
- Downloadthe WEF certificate in a PFX format to your local machine.
- Install your WEF Certificate on the WEF to establish connection.You must install the WEF certificate on every Windows Server, whether DC or not, for the WEFs that are supposed to forward logs to the Windows Event Collector applet on the broker VM.
- Locate the PFX file you downloaded from theCortexXDRconsole and double-click to open theCertificate Import Wizard.
- In theCertificate Import Wizard:
- SelectLocal Machinefollowed byNext.
- Verify theFile namefield displays the PFX certificate file you downloaded and selectNext.
- In thePasswordsfield, enter the Client Certificate Export Password you defined in theCortexXDRconsole followed byNext.
- SelectAutomatically select the certificate store based on the type of certificatefollowed byNextandFinish.
- From a command prompt, runcertlm.msc.
- In the file explorer, navigate toCertificatesand verify the following for each of the folders:
- In thefolder, ensure the certificatePersonalCertificatesforwarder.wec.paloaltonetworks.comappears.
- In thefolder, ensure the CATrusted Root Certification AuthoritiesCertificatesca.wec.paloaltonetworks.comappears.
You can see more than oneca.wec.paloaltonetworks.comandforwarder.wec.paloaltonetworks.comfile from a previous installation in the directory, so select the file with the most extendedExpiration Date. You can verify that you are using the correct certificate:- To verify the client certificate in thefolder is related to the CA, you can select yourPersonalCertificatesforwarder.wec.paloaltonetworks.comfile and from theCertification Pathtab, double-clickca.wec.paloaltonetworks.com. In theDetailstab,Show: Properties only, and verify theThumbprintmatches theca.wec.paloaltonetworks.comfileThumbprint.
- For the Trusted Root Certificate (i.e. CA certificate), you can verify theThumbprintof yourca.wec.paloaltonetworks.comfile matches the Subscription Manage URL by double-clicking the file and from theDetailstab verifying theThumbprint.
- Navigate to.CertificatesPersonalCertificates
- Right-click the certificate and navigate to.All tasksManage Private Keys
- In thePermissionswindow, selectAddand in theEnter the object namesection, enterNETWORK SERVICEfollowed byCheck Namesto verify the object name. The object name is displayed with an underline when valid. and thenOK.
- SelectOK, verify theGroup or user namesappear, and thenApplyPermissions for privet keys.
- Configure the subscription manager.Navigate to, right-clickComputer ConfigurationPoliciesAdministrative Templates: Policy definitionsWindows ComponentsEvent ForwardingConfigure target Subscription Managerand selectEdit.In theConfigure target Subscription Managerwindow:
- MarkConfigure target Subscription ManagerasEnabled.
- In theOptionssection, selectShow, and in theShow Contentswindow, paste the Subscription Manage URL that you copied from theCortexXDRconsole followed byOK.
- SelectApplyandOKto save your changes.
- Complete the WEF Client certificate renewal.On every WEF DC, perform the following from a command prompt.
- Rungpupdate /forceto update the group policy.
- Restart-Service WinRMto apply the configurations.
- Renew your WEC server certificate inCortexXDR.You should only perform this step under the following conditions.
- You have completed the WEF certification renewal process for ALL clients in your environment. Otherwise, events from the WEFs that you did not install the new client certificate will not be collected by the WEC.
- You are approaching the WEC server CA certificate expiration date, which is 2 years after theWindows Event Collectorapplet activation, and receive a notification in theCortexXDRconsole.
- InCortexXDR, select, and locate your broker VM.SettingsConfigurationsData BrokerBroker VMs
- Right-click and select.Windows Event CollectorRenew WEC Server Certificate
- ClickRenew.OnceCortexXDRrenews the WEC server certificate, the status of theWindows Event Collectoron theBroker VMsmachine isActive, Connectedindicating the applet is running. In addition, the health status of the Windows Event Collector applet is now green instead of yellow and the warning message that appeared when you hovered over the health status no longer appears. Your WEC server certificate is issued with a lifespan of 12 months.We also suggest that in XQL Search that you run the following query to verify that your event logs are being captured.dataset =XDR_data | filter _product = "Windows" | fields _vendor,_product,action_evtlog_level,action_evtlog_event_id | sort desc _time | limit 20If this query does not display results with a timestamp from after the renewal process, it could indicate that the renewal process is not complete, so wait a few minutes before running another query. If you are still having a problem, contact Technical Support.
Recommended For You
Recommended Videos
Recommended videos not found.