Professional Documents
Culture Documents
How To - Set Up Central Event Log Monitoring On Windows Server
How To - Set Up Central Event Log Monitoring On Windows Server
How To - Set Up Central Event Log Monitoring On Windows Server
Login
Join
Home
>
Windows
>
General Windows
>
How-tos
patcutrone
Central Event Log Monitoring is free, takes only a few minutes to set up and will let you view event logs for all
your servers in one place.
10 Steps total
Step 1: Determine where all your logs will go
This 'collector' server should be running Windows Server (mine runs 2012 R2) and it should NOT be a DC -
Domain controllers require special configurations and will not work well (or at all) for this task.
Expand
These steps need to be done only once - when you first set up the server to collect all the logs.
Start by logging into your 'collector' machine as a domain administrator and opening a command prompt.
At the prompt type wecutil qc and then press y to confirm service start up mode will be changed to Delay-
Start.
You should receive a message stating that the Windows Event Collector Service was configured Successfully
https://community.spiceworks.com/how_to/159134-how-to-set-up-central-event-log-monitoring-on-windows-server 1/8
9/25/22, 3:10 PM How To - Set up Central Event Log Monitoring on Windows Server - Windows Forum - Spiceworks
Expand
This step can be done either before or after you configure the 'source' computers (the systems which will be
sending the logs). For ease, I chose to do all the steps required on the collector first.
From the expanded Event Viewer menu on the left click the Subscription folder.
From the Action menu in the right pane choose the Create Subscription link
--> b. Leave the Destination Log field set to the default Forwarded Events
--> c. Choose the Collector Initiated radio button and then click Select Computers
--> d. Click on the Add Domain Computers button then type the name of the source computer in the box and
click Check names to confirm, then OK.
------> i. Click the Select Events button in the Events section to bring up the query window.
------>ii. Set Logged to Last 7 days and select the 'critical, 'warning' and 'error' Event Types (or as desired)
------> iii. To forward all application events that occurred in the last 7 days, Select the by log option and check
the boxes next to all Windows logs and only the Hardware Events under Applications and Services and then
click OK to return to the Subscription Properties dialog box. (These are my choices, you may choose what
works for your environment).
------> iv. Click on Advanced then in the Advanced Subscription settings dialog box, select Machine Account
and tick the Minimize Latency radio button then click OK twice to return to the event viewer.
Expand
Expand
--> Log into the 'source' computer as a domain admin and open a command prompt.
-->On the command line type winrm quickconfig - If the service is already running, you will receive a message
in the window confirming.
Expand
For a Standard Server:
--> Select the 'Groups' folder and expand the Event Log Readers group.
-->Click Add. In the Select Users, Computers, Service Accounts, or Groups dialog box, change the Object Type
to Computers and click OK.
--> Search for and add the 'collector' computer to the group, then click Apply and OK to return to the
Computer Management window.
https://community.spiceworks.com/how_to/159134-how-to-set-up-central-event-log-monitoring-on-windows-server 3/8
9/25/22, 3:10 PM How To - Set up Central Event Log Monitoring on Windows Server - Windows Forum - Spiceworks
Expand
If the source computer is a domain controller then the Local Users and Groups option won't appear in
computer Management. Use the below to configure the Event Readers Group in Active Directory Users and
Computers instead:
--> Expand the Domain structure then click on the Builtin folder.
-->Within the Builtin folder, double click on the Event Log Readers group on the center pane of the window.
--> Click on the Members tab then use the Add button.
--> In the Select Users, Computers, Service Accounts, or Groups dialog box, change the Object Type to
Computers and click OK.
--> Search for and add the 'collector' computer to the group, then click the Apply then OK buttons to return to
the Active Directory window
Expand
-- > Open the Control Panel in Category view.
--> Click the System and Security category then the Windows Firewall link.
--> Click the Allowed apps link on the left and add the Remote Event Log Management and Remote Event
Monitor from the list at the Domain level then click on OK.
----> It may be required to click the Change Settings
button in order to be able to make changes to the list.
I wasn't able to get enough detail from any single article so I wrote this guide for my environment using what i
was able to find online. I have put those other articles below as they were instrumental in helping me set this
up.
https://community.spiceworks.com/how_to/159134-how-to-set-up-central-event-log-monitoring-on-windows-server 4/8
9/25/22, 3:10 PM How To - Set up Central Event Log Monitoring on Windows Server - Windows Forum - Spiceworks
I hope I can help others who are having trouble getting their log forwarding set up ;)
References
1st article
2nd article
Follow
Pat Cutrone
254
Contributions
1
Best Answers
5 Comments
dimforest
D3rl
Mar 8th, 2019 at 6:23am
Thanks for the info! Glad was able to bump into this.
Jason1121
https://community.spiceworks.com/how_to/159134-how-to-set-up-central-event-log-monitoring-on-windows-server 5/8
9/25/22, 3:10 PM How To - Set up Central Event Log Monitoring on Windows Server - Windows Forum - Spiceworks
This person is a Verified Professional.
Verify your account
to enable IT peers to see that you are a professional.
Mar 14th, 2019 at 4:21pm
Nice how to.
For anyone that's interested there's a presentation here from Jessica Payne that goes through similar steps.
Takes a while to get to the actual setup but it's worth a listen.
https://web.archive.org/web/20171212201838/https://channel9.msdn.com/Events/Ignite/Australia-
2015/INF327
The volume is extremely low. I ended up downloading it and using VLC to pump the volume up to 200%.
Anthony Tanjoco
Now that you've had this up for a bit -how do you like it now?
-AT
onecogmind
Back to Top
Is it time to jump ship? Tech Gadget that You Wish Snap! ManageEngine vulns,
Potentially new career field? Would Make a Comeback! Exchange Servers hacked,
IT & TECH CAREERS WATER COOLER Group Policies, NyQuil, etc.
https://community.spiceworks.com/how_to/159134-how-to-set-up-central-event-log-monitoring-on-windows-server 6/8
9/25/22, 3:10 PM How To - Set up Central Event Log Monitoring on Windows Server - Windows Forum - Spiceworks
Sorry for making this a long one. It's been Stranger Things Posts: Episode 2
In accordance SPICEWORKS ORIGINALS
brewing for a while though.I have been working with my post about the tech items we have now Your daily dose of tech news, in brief.
at an MSP for nearly eight years. I wish I could that we did not have in the 80’s, I am curious
say it has been a smooth ride. I had to take a what tech has disappeared that you would love
break from work for a semester of college due to see make a comeback? I know that I will
to a panic attack I ha... probably get a lot of r...
Imap vs Pop
COLLABORATION
https://community.spiceworks.com/how_to/159134-how-to-set-up-central-event-log-monitoring-on-windows-server 7/8
9/25/22, 3:10 PM How To - Set up Central Event Log Monitoring on Windows Server - Windows Forum - Spiceworks
COLLABORATION
Load More
https://community.spiceworks.com/how_to/159134-how-to-set-up-central-event-log-monitoring-on-windows-server 8/8