Windows Event Fowarder
This lays out how to create a sbuscription (both source and collector initiated) that collects selected forwarded .evtx event logs from a workstation to a domain controller.
SUMMARY
ENVIRONMENT:
MACHINES:
ASSUMPTIONS:
1. The Source Machine (MSEDGEWIN10) is part of a Domain Controller (WIN-BO2CT95INDP).
2. This guide uses Security Logs as an example.
3. The steps below will create a subscription that collects Security logs from the Source Machine (MSEDGEWIN10).
PROCEDURE:
1. Start the WinRM service
ii. Add the Collector Machine to the Event Log Readers groups
In the Source Machine (MSEDGEWIN10):
iii. Create Subscriptions using Event Viewer
In the Collector Machine (WIN-BO2CT95INDP):
In the Source Machine (WIN-BO2CT95INDP)
Going back to the Collector Machine (WIN-BO2CT95INDP)
REFERENCES:
Last updated