how can i ship my windows logs (event viewer) off to a syslog-ng server

jsctechy used Ask the Experts™
looking to get all my windows server logs (event viewer logs) shipped off to a syslog-ng server
how can i do this? do i need some sort of windows agent installed on the windows boxes to ship them off to the syslog-ng server?

Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Is the native W2K8 event log forwarding what you are looking for?
If so here's an example of what you need to do in terms of configuration.

winrm qc
net localgroup "Event Log Readers" DCNugget1$ /add

wecutil qc
winrm qc

Subscription name: Criticals and Warnings from Nugget2
Destination log: Forwarded Events
Collector initiated
Select Computers -> Nugget2
Select Events -> Critical, Error, Warning
Events Logs -> Applications
User Account: Machine Account
jsctechyInfrastructure Team Lead


thanks motnahp00
what about for older versions of windows? they dont have this capability correct? (windows 2003)
Acronis in Gartner 2019 MQ for datacenter backup

It is an honor to be featured in Gartner 2019 Magic Quadrant for Datacenter Backup and Recovery Solutions. Gartner’s MQ sets a high standard and earning a place on their grid is a great affirmation that Acronis is delivering on our mission to protect all data, apps, and systems.

Windows Server 2003 does not have this capability.
jsctechyInfrastructure Team Lead


do you know of any agents that i can install to ship this to a syslog-ng server?
You can see if there is any integration with Puppet.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial