Windows Enable Log Collector
Revision as of 09:21, 26 June 2019 by Michael.mast (talk | contribs) (Created page with "==Creating the collector== I chose a low volume Windows Server 2016 instance in AWS as the collector. Under event Viewer go to<ref>https://www.petri.com/configure-event-log-fo...")
Creating the collector
I chose a low volume Windows Server 2016 instance in AWS as the collector. Under event Viewer go to[1]
- Subscriptions
- Create Subscription
- Here I used source initiated and selected domain\Domain Computers as the computer group
Though it is a good idea to use the collector initiated option for resiliance, I decided to use source initiated for "reasons". Next create a policy that will get applied to all computers in the domain.[2]
- Under "Computer Configuration\Policies\Administrative Templates\Windows Components\Event Forwarding" add the server
server=yourserver.domain.tld