Enginsite
Overview
Enginsite is used for security monitoring and investigation workflows.
When reviewing Windows events in Enginsite, SIEM records are mapped as:
siem > data lake > ngs.source:windows ereignisprotokollgen.hostname: host name (for cluster cases, this is the specific cluster node)
Access
- Open Enginsite in your browser.
- URL placeholder: add the production Enginsite URL.
- Authenticate using the standard team login flow.
- Auth flow placeholder: document SSO/MFA details for follow-up.
- If access is missing, contact
support@hvcapital.com.
Common Tasks
Export Windows event logs (including cluster nodes)
- In Enginsite, open the relevant Windows event dataset/search.
- Filter to
ngs.source = windows ereignisprotokoll. - Filter
gen.hostnameto the affected host. - For clusters, select the exact cluster node hostname.
- Start export and choose
XMLorCSV. - Wait for export processing to complete (usually a couple of minutes).
- Download and attach the exported file to the incident/ticket as needed.
Troubleshooting
- If no results are returned, re-check source filter
(
windows ereignisprotokoll) and hostname spelling. - If cluster data appears incomplete, verify you exported from the correct
node-specific
gen.hostname. - If export does not finish, retry with a narrower time window and re-run.
- If export options are missing, verify user permissions and Enginsite role.