Avatar of jsctechy
jsctechy
Flag for United States of America asked on

how can i ship my windows logs (event viewer) off to a syslog-ng server

looking to get all my windows server logs (event viewer logs) shipped off to a syslog-ng server
how can i do this? do i need some sort of windows agent installed on the windows boxes to ship them off to the syslog-ng server?

thanks!
Windows Server 2008Windows Server 2003Microsoft Legacy OS

Avatar of undefined
Last Comment
motnahp00

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
motnahp00

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
motnahp00

If so here's an example of what you need to do in terms of configuration.

Forwarder:
winrm qc
net localgroup "Event Log Readers" DCNugget1$ /add

Collector:
wecutil qc
winrm qc

Subscription name: Criticals and Warnings from Nugget2
Destination log: Forwarded Events
Collector initiated
Select Computers -> Nugget2
Select Events -> Critical, Error, Warning
Events Logs -> Applications
User Account: Machine Account
jsctechy

ASKER
thanks motnahp00
what about for older versions of windows? they dont have this capability correct? (windows 2003)
motnahp00

Windows Server 2003 does not have this capability.
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
jsctechy

ASKER
do you know of any agents that i can install to ship this to a syslog-ng server?
motnahp00

You can see if there is any integration with Puppet.