Configure a GPO Windows Server to send to a syslog using SNMP

Posted on 2012-09-07
Last Modified: 2013-09-17
I am trying to configure a GPO that will send windows events to a SolarWinds syslog server. Does anyone have a good GPO/registry template for server 2003/2008 or a way to accomplish this?
Question by:rm-ent
    LVL 39

    Accepted Solution

    I have no windows expertise but this is a huge mashup of words...

    syslog has it's own protocol  and just forwards messages in a certain format.
    SNMP is a query protocol for all kinds of data from SNMP enabled devices.
    Such a device can send traps, [ meant as last gasp message method ].

    Syslog can be received by f.e. kiwisyslog
    maybe splunk is something that is usefull?

    SNMP is quite something else as SYSLOG is all aspects to be considered.
    The only thing they have in common is that both utilize UDP/IP packets...
    LVL 60

    Expert Comment

    LVL 60

    Expert Comment

    not much found with GPO as mentioned in the forum though, they are using log forwarder

    pertaining to above and include a PowerShell Script for Pushing the install of Windows Event Log Forwarder MSI to remote servers

    there is a small piece of open code for sending Windows Eventlog events to a syslog server.
    LVL 12

    Expert Comment


    I think you can use this link as a reference to configure SNMP and Syslog
    LVL 76

    Expert Comment

    The two are a sequence.
    Install snmp on the windos box, use evntwin to configure the eventlog to snmp that you want and export the configuration. The GPO you would then use evntcmd within a startup script to configure each system with the event translations.
    Now, the server where snmptrapd (the receiver for the snmp events will need to be configured to record the received event into syslog on a specific facility in the event you would then configure syslog.conf to direct the received snmp events will be directed into its own file or passed to a program that will parse the vent and record it in a database or generate email or page, etc. notification to alert of a failure.

    Featured Post

    Looking for New Ways to Advertise?

    Engage with tech pros in our community with native advertising, as a Vendor Expert, and more.

    Join & Write a Comment

    Join Greg Farro and Ethan Banks from Packet Pushers ( and Greg Ross from Paessler ( for a discussion about smart network …
    Synchronize a new Active Directory domain with an existing Office 365 tenant
    This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    746 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    17 Experts available now in Live!

    Get 1:1 Help Now