Solved

Windows event forwarding - is there a gpo to configure which events are forwarded?

Posted on 2008-10-04
5
1,377 Views
Last Modified: 2009-12-16
I did not find any word in the vista gpo reference about how to configure which events are forwarded to the eventlog server using a gpo. Did MS skip this?
To make it more clear: I can configure which server to send to by using a gpo but not which events to send while at the client I can do that manually.
0
Comment
Question by:CaptainAhab
5 Comments
 
LVL 5

Expert Comment

by:satyatech
ID: 22644119
Please visit:
http://blogs.technet.com/wincat/archive/2008/08/11/quick-and-dirty-large-scale-eventing-for-windows.aspx

Excerpts:
If Group Policy is not being used, configure the "Subscription type" to be "Collector Initiated". In this case Source Computers will need to be manually added to the Subscription either through the Subscription configuration or the "WECUTIL" command-line utility (which can also be scripted using PowerShell, but that's another topic).

Note: In cases where there Source Computer is generating a large volume of forwarded events (e.g. Security events from a Domain Controller), use WECUTIL on the collector to disable event rendering for the subscription. The task of pre-rendering an event on the source computer can be CPU intensive for a large number of events.
0
 
LVL 53

Expert Comment

by:McKnife
ID: 22644149
I know that page and that is not an answer to my question.
0
 

Author Comment

by:CaptainAhab
ID: 22645023
OK, again swapped accounts here...but anyway. Satyatech, that is not an answer to MY question :)
I found a solution that could be a workaround, so if others are interested, here it is:
--
1 Configure an event forwarding subscrition on your vista computer and call it sup1
2 copy the following file: c:\programdata\microsoft\event viewer\subscriptionfilters\sup1.xml and place it into the folder at the target computer
3 export the following regfile and import it at the target computer: HKLM\software\microsoft\windows\currentversion\eventcollector\subscriptions\sup1
4 execute the following command at the client (from an elevated command prompt):wecutil rs sup1
Done!

I will squeeze these commands and files and regkeys into an msi and distribute it - no problem.

I will keep this question open in case anyone could tell if MS has a GPO for it.
0
 
LVL 1

Accepted Solution

by:
Computer101 earned 0 total points
ID: 22858984
PAQed with points refunded (250)

Computer101
EE Admin
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Event Viewer: MMC Could not create the snap-in, Win7 Pro 6 61
Account Lockouts 25 145
Setup DFS on One Server with Multiple Shares 7 36
system state backup 1 30
I was supporting a handful of Windows 2008 (non-R2) 2 node clusters with shared quorum disks. Some had SQL 2008 installed and some were just a vendor application that we supported. For the purposes of this article it doesn’t really matter which so w…
I'm a big fan of Windows' offline folder caching and have used it on my laptops for over a decade.  One thing I don't like about it, however, is how difficult Microsoft has made it for the cache to be moved out of the Windows folder.  Here's how to …
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

919 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now