For source-initiated subscriptions, which tool do you use to configure event forwarding?
IntroductionThe Windows Event Collector (WEC) acts as a log collector and forwarder tool for the Microsoft Windows platform. It collects the log messages of Windows-based hosts over HTTPS (using TLS encryption and mutual authentication), and forwards them to a syslog-ng PE server. In Windows terminology, this tool allows you to define source-initiated push subscriptions, and have them forwarded to a syslog-ng PE server. For details on the limitations of WEC, see Limitations Show Unlike the syslog-ng Agent for Windows, the Windows Event Collector is a standalone tool that does not require installing on the Windows-based host itself. This can be an advantage when your organization's policies restrict or do not allow the installation of third-party tools. Another difference between the Windows Event Collector tool and syslog-ng Agent for Windows is that WEC forwards logs only about Windows events, while syslog-ng Agent forwards both Windows event logs as well as files from Windows hosts to the syslog-ng PE server. The Windows Event Collector sits between your Windows hosts and your syslog-ng Premium Edition server, accepting log messages from the remote Windows side with WinRM and feeding them to syslog-ng Premium Edition 7.0. Figure 1: How Windows Event Collector works in syslog-ng PE 7.0 At a high level, this is how you can get Windows event logs to be forwarded to your syslog-ng Premium Edition server using the WEC tool:
Install the Windows Event CollectorPrerequisites:
Purpose: The Windows Event Collector is bundled into the syslog-ng PE installers from version 7.0.6 onward. A SysV init script and a systemd service file are provided and installed automatically, so by installing syslog-ng PE, you also install WEC. However, syslog-ng-wec is not registered to start at boot. Steps:
Generate SSL certificates for Windows Event CollectorPurpose:When the Windows-based host and the Windows Event Collector start communicating for the first time, they authenticate each other by exchanging and verifying each other's certificates. The process begins with the Windows host requesting and verifying the WEC tool's certificates. After successful verification, the Windows host sends its own certificates for verification to WEC.
The example described in this section uses OpenSSL for certificate generation. Note, however, that you can generate certificates using the Windows Public Key Infrastructure (PKI). To generate the SSL certificates for WEC, complete the following steps: Steps:
Configure event source computersPrerequisites:
Purpose: When collecting event logs from Windows hosts, the Windows clients sending logs act as the event source computers. The WEC tool collects and forwards messages from the standard Windows eventlog containers. There is no restriction on the number of Windows hosts that can connect to the Windows Event Collector. To configure your event sources, complete the following steps. Steps:
The document was helpful. Select Rating I easily found the information I needed. Select Rating Which tool do you use to configure event forwarding?Luckily, you have a tool called Windows Event Forwarding (WEF) to make things easier. The event log forwarding in Windows Server allows system administrators to centralize client and server event logs, making it easier to monitor events without connecting to each server individually.
How do you set up forwarding events?This is one way to configure Windows Event forwarding.. Enter a name and description for the subscription.. For Destination Log, confirm that Forwarded Events is selected. ... . Select Source computer initiated and click Select Computers Groups. ... . Click Select Events.. What is source initiated subscription?Source-initiated subscriptions allow you to define a subscription on an event collector computer without defining the event source computers, and then multiple remote event source computers can be set up (using a group policy setting) to forward events to the event collector computer.
Which two types of service accounts must you use to set up event subscriptions?Which TWO types of service accounts must you use to set up event subscriptions? You would choose a default machine account and specific user service account.
|