Based on the searching I have done so far, I may be asking for the impossible...but it's worth a shot:
I have a ton of Windows based servers in my environment (primarily Server 2008 R2 and Server 2012 R2). The bulk of them are virtual machines (hosted on VMware esxi). All of them have Microsoft System Center agents installed on them.
I have been tasked with trying to send all Windows event log entries to a SIEM (specifically Sagan from Quadrant) in a syslog format, without using an additional agent on each guest OS.
I would like to hear from anyone that has a creative solution to meet that need. It could include somehow using the existing vmtools or System Center agents to collect the logs and send them off. Honestly, it could also include sending the event logs to Sagan without being in the syslog format, as long as Sagan will support it. Effectively, if you can get event entries from a Windows OS to Sagan with no agent; you'll get points.
Thanks in advance for any help!