Log
monitoring
traffic:
This
traffic
occurs
between
the
agent
and
an
Active
Directory
Domain
Controller
or
Exchange
CAS.
The
content
of
this
traffic
is
the
entirety
of
the
servers
Security
Logs.
Based
on
the
“Security
Log
Monitor
Frequency”
value
configured
on
the
agent
this
traffic
consists
of
an
authenticated
TCP
based
WMI
connection
to
the
server
that
fetches
the
new
logs
since
the
last
check.