Skip to content

Centralize Windows Events with Source-Initiated Forwarding

Windows Event Forwarding (WEF) can centralize selected Windows events without installing a separate forwarding agent. In a source-initiated subscription, the collector defines the subscription and domain clients learn the collector address through Group Policy.

Pilot with a small computer group and a low-volume log such as System warnings and errors before collecting security events broadly. Event volume, retention, access control, and bandwidth should be planned for the collector.


Step 1: Prepare the Collector

01

Enable Windows Event Collector and WinRM

Collector

On the designated collector, open an elevated Command Prompt. Configure WinRM and the Event Collector service, then verify the collector service state. Keep the collector on a trusted management network and allow the required Windows Remote Management traffic only from approved domain devices.

Terminal window
winrm qc -q
wecutil qc /q
sc query wecsvc
❯ View Expected Console Output
SERVICE_NAME: wecsvc
STATE : 4 RUNNING

Step 2: Create a Low-Volume Source-Initiated Subscription

02

Filter the Events Before Forwarding Them

Subscription

In Event Viewer on the collector, open Subscriptions and create a subscription. Choose Source computer initiated, select a pilot computer group, and start with System warning and error events. This keeps the initial test bounded while validating policy and connectivity.

Windows Event Viewer Subscription Properties showing Source computer initiated configuration

Figure 1: Event Viewer Subscription Properties dialog defining source computer initiated parameters, computer groups, and event severity filters.

Subscription type: Source computer initiated
Destination log: ForwardedEvents
Source computer group: WEF-Pilot-Computers
Selected log: System
Event levels: Critical, Error, Warning
❯ View Expected Console Output
Subscription created on the collector for the pilot computer group.

Step 3: Point Pilot Clients to the Collector

03

Configure Subscription Manager in Group Policy

Group Policy

Create or edit a computer GPO linked only to the pilot computers. Enable Computer Configuration > Policies > Administrative Templates > Windows Components > Event Forwarding > Configure target Subscription Manager. Enter the collector’s fully qualified domain name and use the documented WEC URL form.

Group Policy Management Editor configuring target Subscription Manager

Figure 2: GPO Configure target Subscription Manager setting pointing endpoints to the collector FQDN over port 5985.

Server=http://wec01.contoso.com:5985/wsman/SubscriptionManager/WEC,Refresh=60
Terminal window
gpupdate /target:computer /force
❯ View Expected Console Output
Computer Policy update has completed successfully.

Step 4: Confirm Client and Collector Status

04

Verify the Source Connected and Events Arrived

Verification

Allow time for the configured refresh interval. On a pilot client, inspect the Eventlog-ForwardingPlugin Operational log for a successful subscription connection. On the collector, check the subscription runtime status and query ForwardedEvents for the pilot host.

Windows Event Viewer ForwardedEvents log populated with client events

Figure 3: Event Viewer ForwardedEvents log populated with incoming events showing client computer hostnames and details.

Terminal window
wecutil gr WEF-Pilot-System-Events
Terminal window
Get-WinEvent -LogName ForwardedEvents -MaxEvents 20 |
Select-Object TimeCreated, MachineName, Id, LevelDisplayName
❯ View Expected Console Output
Runtime status reports the pilot source as active; forwarded records show the source machine name.

See Microsoft’s source-initiated subscription guide and wecutil reference for configuration and runtime status details.

Comments